ZeroHour

CVE-2026-87650

mass

Out-of-Bounds Read in Google Chrome WebGL Allows Potential Sandbox-Escape RCE

CVSS 3.1
9.6 critical
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-87650 is an out-of-bounds read (CWE-125) in the WebGL component of Google Chrome, patched in release 153.0.8010.36 as part of a set of 230 security fixes. A remote attacker can trigger the flaw by luring a user to open a crafted HTML page that exercises the vulnerable WebGL code path. Successful exploitation could allow arbitrary code execution outside the browser sandbox, which is a significant privilege escalation relative to typical sandboxed renderer attacks. Users of Google Chrome versions prior to 153.0.8010.36 on all platforms are affected. The flaw carries a Chromium 'High' severity rating; EPSS currently estimates only a 0.3% chance of exploitation within 30 days and it is not in CISA's KEV, but public reporting around the Chrome 153 release indicates a zero-day was exploited in the wild at that time.

What to do: Update Google Chrome to version 153.0.8010.36 or later immediately; verify the installed version via chrome://settings/help and ensure auto-update is enabled. Enterprise administrators should push the update via MDM/GPO and prioritize systems with internet-facing or general web-browsing users. Until patched, exercise caution with untrusted web content, as the flaw is triggered by a crafted HTML page.

Affected
Google Chromeprior to 153.0.8010.36
Estimated exposure
mass≈3 billion+ users (Chrome's global installed base of unpatched versions) — Chrome is the world's dominant desktop browser with roughly 60-65% market share and an installed base measured in billions, so virtually any unpatched Chrome user browsing the web is potentially exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out of bounds read in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

Google Chrome 153 Released With 230 Security Fixes and Zero-Day Exploited in the Wild

Google released Chrome 153 with 230 security fixes, patching CVE-2026-87491, a V8 out-of-bounds write zero-day actively exploited in the wild.

Google shipped Chrome 153 (153.0.8010.36/.37) for Windows, macOS, and Linux with 230 security fixes, including CVE-2026-87491, a medium-severity V8 out-of-bounds write being exploited in the wild. The release also fixes five critical vulnerabilities: four in WebGL (two use-after-frees, an out-of-bounds write, a buffer overflow) and one use-after-free in Cast. High-severity V8 use-after-free and type-confusion defects are among the fixes, and Google has restricted technical details until most users are patched. Administrators should verify deployed versions on managed endpoints, as Chrome-derived browsers may follow different patch schedules.

GBHackers · 6d agoExploit / PoC in the wildCVE-2026-87491CVE-2026-87464CVE-2026-87488+19 CVEs