AI analysis
CVE-2026-87657 is a use-after-free (CWE-416) in the V8 JavaScript engine of Google Chrome, fixed in Chrome 153.0.8010.36 as part of a release containing 230 security fixes. A remote attacker triggers the flaw via a crafted HTML page that causes the memory-reuse error in V8, and the bug is exploitable only after the attacker has already compromised the renderer process. Successful exploitation lets the attacker read memory inside the Chrome sandbox, an information-disclosure impact limited to confidentiality with no indication of privilege escalation or code execution outside the sandbox (CVSS 3.1: 3.1, Medium Chromium severity). Anyone running Chrome prior to 153.0.8010.36 is affected, which effectively means nearly the entire Chrome install base until updates are applied. Related reporting on the Chrome 153 release mentions a zero-day exploited in the wild, but no public proof-of-concept exists, the flaw is not in CISA KEV, and the available data does not confirm whether this specific CVE is the actively exploited one.
What to do: Update Google Chrome to 153.0.8010.36 or later on all endpoints, verifying the running version via chrome://settings/help or enterprise update management. Given related reporting of an in-the-wild zero-day in this release, prioritize patching for high-risk and internet-facing users. No workarounds are identified beyond updating; Chrome's sandbox limits the impact to in-sandbox memory reads, but the bug requires a prior renderer compromise, so treat it as a likely component of an exploit chain.
Affected
| Google Chrome | All versions prior to 153.0.8010.36 |
Estimated exposure
mass≈3 billion Chrome users (essentially the entire Chrome install base on versions before 153.0.8010.36) — Chrome runs on roughly 3 billion devices worldwide, and every installation not yet updated to 153.0.8010.36 falls within the affected version range.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.