ZeroHour

CVE-2026-87639

mass

Use-After-Free in Google Chrome's WebPackaging Enables Sandbox Escape

CVSS 3.1
8.3 high
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-87639 is a use-after-free (CWE-416) in the WebPackaging component of Google Chrome in versions prior to 153.0.8010.36. It is triggered when a compromised renderer process processes a crafted HTML page that triggers the memory-safety flaw; an attacker cannot use this bug alone but must first compromise the renderer (e.g., via a separate renderer or V8 exploit). If successfully exploited, the attacker gains the ability to execute arbitrary code outside Chrome's sandbox, breaking the browser's sandbox boundary and potentially compromising the underlying system. Users and organizations running Google Chrome builds earlier than 153.0.8010.36 are affected. Exploitation status: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS is low at 0.3%, though related news reports a separate Chrome V8 zero-day exploited in the wild that could serve as the required renderer-compromise first stage.

What to do: Update Google Chrome to 153.0.8010.36 or later (verify via chrome://settings/help and restart the browser to apply); enterprises should push the update promptly and inventory for users on older builds. Because this bug requires a prior renderer-process compromise, also ensure Chrome and all renderer-affecting components (e.g., V8) are fully patched, as in-the-wild V8 zero-day exploitation has been reported. No known mitigations beyond updating; no public proof-of-concept exists.

Affected
google chromeall versions prior to 153.0.8010.36
Estimated exposure
masshundreds of millions to billions of Chrome installations potentially affected (all desktop Chrome users on builds earlier than 153.0.8010.36) — Chrome holds roughly two-thirds of global browser market share, implying a user base in the hundreds of millions to billions, though rapid auto-updates shrink the population of unpatched builds; the exact count of out-of-date installs is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google patches actively exploited Chrome V8 zero-day CVE-2026-87491, an out-of-bounds write enabling sandboxed code execution via crafted HTML pages.

Google released Chrome 153.0.8010.36/.37 fixing 230 vulnerabilities, including CVE-2026-87491, an out-of-bounds write in the V8 engine that allowed remote code execution inside the sandbox via a crafted HTML page and is confirmed to be exploited in the wild. The flaw was reported on August 6, 2026 by Jihyeon Jeong of Compsec Lab, Seoul National University, who received a $2,500 bug bounty. This is the seventh actively exploited Chrome zero-day of 2026. The update also fixes five critical flaws in WebGL and Cast, plus a high WebPackaging use-after-free (CVE-2026-87639) credited to OpenAI Codex Security.

The Hacker News · 7d agoExploit / PoC in the wildCVE-2026-87491CVE-2026-2441CVE-2026-3909+10 CVEs