CVE-2026-87638
massOut-of-Bounds Write in Google Chrome Media Allows Potential Sandbox RCE
CVE-2026-87638 is an out-of-bounds write (CWE-787) in the Media component of Google Chrome, fixed in version 153.0.8010.36. A remote attacker can trigger it by getting a user to open a crafted HTML page, causing memory corruption in the media handling code. Successful exploitation could allow the attacker to execute arbitrary code outside the Chrome sandbox, though Google labels this 'potentially' exploitable and rates it Medium in Chromium severity terms, while the assigned CVSS 3.1 score of 9.6 (critical, with changed scope) reflects the worst-case sandbox-escape RCE impact. Anyone running Google Chrome prior to 153.0.8010.36 is affected. There is currently no known exploitation in the wild, no public proof-of-concept, and EPSS estimates only a 0.3% chance of exploitation within 30 days.
What to do: Update Chrome to 153.0.8010.36 or later and restart the browser to load the patched version; verify the version via chrome://version or your endpoint/MDM inventory. If immediate patching is not possible, exercise caution with untrusted web content and rely on site isolation and safe-browsing controls as partial mitigations. Because there is no known in-the-wild exploitation or public PoC, routine patch cycles are adequate, but prioritize managed fleets that have auto-update disabled.
| Google Chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out of bounds write in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.