CVE-2026-87646
massUse-after-free in Google Chrome Web Authentication enables sandbox-escaping RCE
CVE-2026-87646 is a use-after-free memory-corruption flaw (CWE-416) in the Web Authentication component of Google Chrome. A remote attacker can trigger it by convincing a user to open a crafted HTML page, which corrupts memory during WebAuthn processing. Successful exploitation yields arbitrary code execution outside Chrome's sandbox, giving the attacker code execution on the host at the browser's privileges rather than being confined to the renderer sandbox. All users running Google Chrome prior to 153.0.8010.36 are affected. Exploitation is not currently confirmed: there is no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days.
What to do: Update Chrome to 153.0.8010.36 or later (check via chrome://settings/help) as soon as the patched build reaches your channel, since the high CVSS score and sandbox-escape impact warrant prompt patching even without known exploitation. In managed environments, verify that auto-update actually delivered the fixed build and enforce the minimum version via enterprise browser-update policies; until patched, limit exposure by discouraging visits to untrusted web pages.
| Google Chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.