ZeroHour

CVE-2026-87654

mass

Sandbox-Escaping Buffer Overflow in Google Chrome ANGLE on Windows

CVSS 3.1
9.6 critical
EPSS
<1%p29
Published
()
Modified
AI analysis

Google Chrome on Windows prior to 153.0.8010.36 contains a buffer overflow (CWE-122) in ANGLE, the graphics shader-translation layer Chrome uses for WebGL and GPU rendering. A remote attacker can trigger the flaw by persuading a user to open a crafted HTML page, causing memory corruption in the ANGLE component. Successful exploitation allows the attacker to execute arbitrary code outside the Chrome sandbox, meaning code runs with broader host-level privileges rather than being confined to the browser renderer. All Chrome users on Windows running affected builds are exposed; the advisory scope does not state impact for other operating systems. The flaw carries a Chromium 'High' severity rating and a critical CVSS 9.6 score; EPSS currently estimates only a 0.3% chance of exploitation in the next 30 days and it is not in CISA KEV, but release coverage of Chrome 153 reports a zero-day exploited in the wild, though public confirmation tying that activity to this specific bug is limited.

What to do: Update Chrome on Windows to 153.0.8010.36 or later (via chrome://settings/help or your managed update channel); the fix ships in Chrome 153, which includes 230 security fixes. Since the bug is triggered via web content and exploitation outside the sandbox is reported, prioritize patching internet-facing user fleets and confirm no clients remain on pre-153 builds.

Affected
google chromeChrome on Windows prior to 153.0.8010.36
Estimated exposure
massbillions of users (Chrome has roughly 3+ billion users; Windows is its largest desktop platform) — Chrome holds roughly 65% global browser market share across an estimated 3-4 billion users, and Windows is its largest desktop platform, so every Windows user not yet on 153.0.8010.36 is plausibly affected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

Google Chrome 153 Released With 230 Security Fixes and Zero-Day Exploited in the Wild

Google released Chrome 153 with 230 security fixes, patching CVE-2026-87491, a V8 out-of-bounds write zero-day actively exploited in the wild.

Google shipped Chrome 153 (153.0.8010.36/.37) for Windows, macOS, and Linux with 230 security fixes, including CVE-2026-87491, a medium-severity V8 out-of-bounds write being exploited in the wild. The release also fixes five critical vulnerabilities: four in WebGL (two use-after-frees, an out-of-bounds write, a buffer overflow) and one use-after-free in Cast. High-severity V8 use-after-free and type-confusion defects are among the fixes, and Google has restricted technical details until most users are patched. Administrators should verify deployed versions on managed endpoints, as Chrome-derived browsers may follow different patch schedules.

GBHackers · 6d agoExploit / PoC in the wildCVE-2026-87491CVE-2026-87464CVE-2026-87488+19 CVEs