ZeroHour

Vulnerabilities

230 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-87643
Integer Overflow in Google Chrome GPU on Android Allows Sandbox Escape

CVE-2026-87643 is an integer overflow (CWE-190) in the GPU component of Google Chrome on Android, fixed in Chrome 153.0.8010.36. An attacker triggers the flaw by persuading a user to open a crafted HTML page, causing the malicious content to be processed by the vulnerable GPU code path. Successful exploitation could let a remote attacker execute arbitrary code outside the Chrome sandbox, meaning code would run with broader privileges than the browser's normal per-tab sandboxing permits. Only Chrome on Android is affected per the advisory, while Google's Chromium team rates the flaw Medium even though the published CVSS 3.1 score is 9.6 (critical). No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is currently known, and EPSS estimates only a 0.3% probability of exploitation within the next 30 days.

Do: Update Chrome on Android to version 153.0.8010.36 or later, delivered through Google Play or your enterprise mobile update channel, and verify the installed version on managed devices. Until patched, treat untrusted websites with caution on Android endpoints. Given the absence of known exploitation and the Medium Chromium severity, routine patch-cycle timing is defensible, but GPU sandbox-escape bugs are a common exploitation vector once details become public, so prioritize the update.

9.6
group max
<1%
  • Google Chrome for Android All versions prior to 153.0.8010.36
mass≈1 billion or more Android devices with Chrome installed, though only the subset not yet updated to 153.0.8010.36 remains vulnerable