ZeroHour

CVE-2026-87638

mass

Out-of-Bounds Write in Google Chrome Media Allows Potential Sandbox RCE

CVSS 3.1
9.6 critical
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-87638 is an out-of-bounds write (CWE-787) in the Media component of Google Chrome, fixed in version 153.0.8010.36. A remote attacker can trigger it by getting a user to open a crafted HTML page, causing memory corruption in the media handling code. Successful exploitation could allow the attacker to execute arbitrary code outside the Chrome sandbox, though Google labels this 'potentially' exploitable and rates it Medium in Chromium severity terms, while the assigned CVSS 3.1 score of 9.6 (critical, with changed scope) reflects the worst-case sandbox-escape RCE impact. Anyone running Google Chrome prior to 153.0.8010.36 is affected. There is currently no known exploitation in the wild, no public proof-of-concept, and EPSS estimates only a 0.3% chance of exploitation within 30 days.

What to do: Update Chrome to 153.0.8010.36 or later and restart the browser to load the patched version; verify the version via chrome://version or your endpoint/MDM inventory. If immediate patching is not possible, exercise caution with untrusted web content and rely on site isolation and safe-browsing controls as partial mitigations. Because there is no known in-the-wild exploitation or public PoC, routine patch cycles are adequate, but prioritize managed fleets that have auto-update disabled.

Affected
Google Chromeall versions prior to 153.0.8010.36
Estimated exposure
massbillions of Chrome users; all installs on builds before 153.0.8010.36 are vulnerable until auto-updated — Chrome has a global user base estimated at over 3 billion across desktop and mobile, and although most installs auto-update quickly, any fleet on pre-153.0.8010.36 builds is exposed, making this mass-scale by install count.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.