ZeroHour

CVE-2026-87636

mass

Type Confusion in XML in Google Chrome Allows Sandboxed Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p23
Published
()
Modified
AI analysis

CVE-2026-87636 is a type confusion flaw (CWE-843) in Google Chrome's XML handling, which can cause the browser to misinterpret data types while parsing XML content. An attacker triggers it by luring a user to a crafted HTML page containing malicious XML, with no privileges required but user interaction needed. If exploited, the attacker can potentially execute arbitrary code inside the Chrome sandbox, which limits the impact of any resulting code execution to the compromised renderer process rather than the host system. Users of Google Chrome on versions prior to 153.0.8010.36 are affected. There is currently no evidence of in-the-wild exploitation, no known public proof-of-concept, and a low EPSS score (0.3%), and Google rates the flaw as Medium severity in its own scale.

What to do: Update Google Chrome to version 153.0.8010.36 or later, which is available via Chrome's auto-update; users can verify their version at chrome://settings/help or chrome://version. Enterprise administrators should confirm via update management tooling that all managed endpoints have received the 153.0.8010.36 build. Because exploitation requires user interaction, remind users to avoid clicking links from untrusted sources until updates are confirmed.

Affected
google chromeall versions prior to 153.0.8010.36
Estimated exposure
masshundreds of millions to billions of users (Chrome holds roughly 65% global browser share with an installed base in the billions) — Chrome's dominant global browser market share and multi-billion-user installed base make this a mass-scale exposure, though the sandbox limits actual impact per successful exploit.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.