ZeroHour

CVE-2026-87657

mass

Use-After-Free in Google Chrome's V8 Engine Allows In-Sandbox Memory Disclosure

CVSS 3.1
3.1 low
EPSS
<1%p7
Published
()
Modified
AI analysis

CVE-2026-87657 is a use-after-free (CWE-416) in the V8 JavaScript engine of Google Chrome, fixed in Chrome 153.0.8010.36 as part of a release containing 230 security fixes. A remote attacker triggers the flaw via a crafted HTML page that causes the memory-reuse error in V8, and the bug is exploitable only after the attacker has already compromised the renderer process. Successful exploitation lets the attacker read memory inside the Chrome sandbox, an information-disclosure impact limited to confidentiality with no indication of privilege escalation or code execution outside the sandbox (CVSS 3.1: 3.1, Medium Chromium severity). Anyone running Chrome prior to 153.0.8010.36 is affected, which effectively means nearly the entire Chrome install base until updates are applied. Related reporting on the Chrome 153 release mentions a zero-day exploited in the wild, but no public proof-of-concept exists, the flaw is not in CISA KEV, and the available data does not confirm whether this specific CVE is the actively exploited one.

What to do: Update Google Chrome to 153.0.8010.36 or later on all endpoints, verifying the running version via chrome://settings/help or enterprise update management. Given related reporting of an in-the-wild zero-day in this release, prioritize patching for high-risk and internet-facing users. No workarounds are identified beyond updating; Chrome's sandbox limits the impact to in-sandbox memory reads, but the bug requires a prior renderer compromise, so treat it as a likely component of an exploit chain.

Affected
Google ChromeAll versions prior to 153.0.8010.36
Estimated exposure
mass≈3 billion Chrome users (essentially the entire Chrome install base on versions before 153.0.8010.36) — Chrome runs on roughly 3 billion devices worldwide, and every installation not yet updated to 153.0.8010.36 falls within the affected version range.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

In the news

Google Chrome 153 Released With 230 Security Fixes and Zero-Day Exploited in the Wild

Google released Chrome 153 with 230 security fixes, patching CVE-2026-87491, a V8 out-of-bounds write zero-day actively exploited in the wild.

Google shipped Chrome 153 (153.0.8010.36/.37) for Windows, macOS, and Linux with 230 security fixes, including CVE-2026-87491, a medium-severity V8 out-of-bounds write being exploited in the wild. The release also fixes five critical vulnerabilities: four in WebGL (two use-after-frees, an out-of-bounds write, a buffer overflow) and one use-after-free in Cast. High-severity V8 use-after-free and type-confusion defects are among the fixes, and Google has restricted technical details until most users are patched. Administrators should verify deployed versions on managed endpoints, as Chrome-derived browsers may follow different patch schedules.

GBHackers · 6d agoExploit / PoC in the wildCVE-2026-87491CVE-2026-87464CVE-2026-87488+19 CVEs