CVE-2026-87643
massInteger Overflow in Google Chrome GPU on Android Allows Sandbox Escape
CVE-2026-87643 is an integer overflow (CWE-190) in the GPU component of Google Chrome on Android, fixed in Chrome 153.0.8010.36. An attacker triggers the flaw by persuading a user to open a crafted HTML page, causing the malicious content to be processed by the vulnerable GPU code path. Successful exploitation could let a remote attacker execute arbitrary code outside the Chrome sandbox, meaning code would run with broader privileges than the browser's normal per-tab sandboxing permits. Only Chrome on Android is affected per the advisory, while Google's Chromium team rates the flaw Medium even though the published CVSS 3.1 score is 9.6 (critical). No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is currently known, and EPSS estimates only a 0.3% probability of exploitation within the next 30 days.
What to do: Update Chrome on Android to version 153.0.8010.36 or later, delivered through Google Play or your enterprise mobile update channel, and verify the installed version on managed devices. Until patched, treat untrusted websites with caution on Android endpoints. Given the absence of known exploitation and the Medium Chromium severity, routine patch-cycle timing is defensible, but GPU sandbox-escape bugs are a common exploitation vector once details become public, so prioritize the update.
| Google Chrome for Android | All versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.