CVE-2026-87637
massUse-after-free in Google Chrome Extensions on Mac enables sandbox-escaped RCE
CVE-2026-87637 is a use-after-free (CWE-416) in the Extensions component of Google Chrome on macOS, fixed in Chrome 153.0.8010.36. It is triggered remotely when a user's browser loads a crafted HTML page, which corrupts memory in the affected component. An attacker who successfully exploits it can execute arbitrary code outside the Chrome sandbox on the Mac, meaning a compromise that escapes Chrome's renderer isolation rather than remaining confined to a browser tab. Only Chrome builds prior to 153.0.8010.36 on Mac are affected per the advisory; Chrome on other operating systems is not listed. As of this analysis there is no public proof-of-concept, the issue is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.3%, with no confirmed reports of in-the-wild exploitation.
What to do: Update Chrome on Mac to 153.0.8010.36 or later (check chrome://settings/help or use enterprise update management) and restart the browser to complete the update. No workarounds are documented, so unpatched Macs should be treated as carrying residual risk until updated, and users should avoid opening untrusted links in the interim. Enterprises should verify patched versions across managed Mac fleets using MDM/EMM browser-version reporting.
| google chrome | Chrome on Mac (macOS) prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.