AI analysis
CVE-2026-87639 is a use-after-free (CWE-416) in the WebPackaging component of Google Chrome in versions prior to 153.0.8010.36. It is triggered when a compromised renderer process processes a crafted HTML page that triggers the memory-safety flaw; an attacker cannot use this bug alone but must first compromise the renderer (e.g., via a separate renderer or V8 exploit). If successfully exploited, the attacker gains the ability to execute arbitrary code outside Chrome's sandbox, breaking the browser's sandbox boundary and potentially compromising the underlying system. Users and organizations running Google Chrome builds earlier than 153.0.8010.36 are affected. Exploitation status: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS is low at 0.3%, though related news reports a separate Chrome V8 zero-day exploited in the wild that could serve as the required renderer-compromise first stage.
What to do: Update Google Chrome to 153.0.8010.36 or later (verify via chrome://settings/help and restart the browser to apply); enterprises should push the update promptly and inventory for users on older builds. Because this bug requires a prior renderer-process compromise, also ensure Chrome and all renderer-affecting components (e.g., V8) are fully patched, as in-the-wild V8 zero-day exploitation has been reported. No known mitigations beyond updating; no public proof-of-concept exists.
Affected
| google chrome | all versions prior to 153.0.8010.36 |
Estimated exposure
masshundreds of millions to billions of Chrome installations potentially affected (all desktop Chrome users on builds earlier than 153.0.8010.36) — Chrome holds roughly two-thirds of global browser market share, implying a user base in the hundreds of millions to billions, though rapid auto-updates shrink the population of unpatched builds; the exact count of out-of-date installs is…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.