ZeroHour

CVE-2026-87643

mass

Integer Overflow in Google Chrome GPU on Android Allows Sandbox Escape

CVSS 3.1
9.6 critical
EPSS
<1%p33
Published
()
Modified
AI analysis

CVE-2026-87643 is an integer overflow (CWE-190) in the GPU component of Google Chrome on Android, fixed in Chrome 153.0.8010.36. An attacker triggers the flaw by persuading a user to open a crafted HTML page, causing the malicious content to be processed by the vulnerable GPU code path. Successful exploitation could let a remote attacker execute arbitrary code outside the Chrome sandbox, meaning code would run with broader privileges than the browser's normal per-tab sandboxing permits. Only Chrome on Android is affected per the advisory, while Google's Chromium team rates the flaw Medium even though the published CVSS 3.1 score is 9.6 (critical). No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is currently known, and EPSS estimates only a 0.3% probability of exploitation within the next 30 days.

What to do: Update Chrome on Android to version 153.0.8010.36 or later, delivered through Google Play or your enterprise mobile update channel, and verify the installed version on managed devices. Until patched, treat untrusted websites with caution on Android endpoints. Given the absence of known exploitation and the Medium Chromium severity, routine patch-cycle timing is defensible, but GPU sandbox-escape bugs are a common exploitation vector once details become public, so prioritize the update.

Affected
Google Chrome for AndroidAll versions prior to 153.0.8010.36
Estimated exposure
mass≈1 billion or more Android devices with Chrome installed, though only the subset not yet updated to 153.0.8010.36 remains vulnerable — Chrome is the default or primary browser on the vast majority of Android devices, giving it an install base in the billions, and the Android-only scope still leaves an enormous population, albeit one that shrinks rapidly because Chrome…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.