ZeroHour

CVE-2026-87637

mass

Use-after-free in Google Chrome Extensions on Mac enables sandbox-escaped RCE

CVSS 3.1
9.6 critical
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-87637 is a use-after-free (CWE-416) in the Extensions component of Google Chrome on macOS, fixed in Chrome 153.0.8010.36. It is triggered remotely when a user's browser loads a crafted HTML page, which corrupts memory in the affected component. An attacker who successfully exploits it can execute arbitrary code outside the Chrome sandbox on the Mac, meaning a compromise that escapes Chrome's renderer isolation rather than remaining confined to a browser tab. Only Chrome builds prior to 153.0.8010.36 on Mac are affected per the advisory; Chrome on other operating systems is not listed. As of this analysis there is no public proof-of-concept, the issue is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.3%, with no confirmed reports of in-the-wild exploitation.

What to do: Update Chrome on Mac to 153.0.8010.36 or later (check chrome://settings/help or use enterprise update management) and restart the browser to complete the update. No workarounds are documented, so unpatched Macs should be treated as carrying residual risk until updated, and users should avoid opening untrusted links in the interim. Enterprises should verify patched versions across managed Mac fleets using MDM/EMM browser-version reporting.

Affected
google chromeChrome on Mac (macOS) prior to 153.0.8010.36
Estimated exposure
masshundreds of millions of users (Chrome's global user base is on the order of 3+ billion, and macOS is a substantial minority share) — Chrome is the world's most widely used browser with a user base in the billions and broad desktop market share, and the large installed population of Chrome-on-Mac users implies a mass-scale affected audience even though exploitation…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.