CVE-2026-87464: RCE outside sandbox in Chromium prior to 153.0.8010.36
CVE-2026-87464 is a critical use-after-free in Chrome's WebGL allowing sandbox-escaping RCE via crafted HTML pages, fixed in 153.0.8010.36.
Google Chrome prior to 153.0.8010.36 contains a use-after-free in WebGL that allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. Google rates it as Chromium security severity Critical, though tracker details are restricted. Debian indicates all current Chromium packages are affected, and the flaw likely impacts Chromium-derived browsers. No active exploitation is mentioned in the disclosure.
- Use-after-free in WebGL enables code execution outside the Chrome sandbox
- Exploitation requires luring users to a crafted HTML page
- No exploitation observed or claimed in the disclosure
- Debian indicates Chromium derivatives are also affected
- Fix is available in version 153.0.8010.36
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-87464 | Use-After-Free in WebGL in Google Chrome Allows Code Execution Outside the Sandbox CVE-2026-87464 is a use-after-free (CWE-416) in the WebGL component of Google Chrome affecting versions prior to 153.0.8010.36. A remote attacker can trigger it by luring a user to open a crafted HTML page, which corrupts memory in the browser's WebGL rendering path. Successful exploitation allows arbitrary code execution outside the browser sandbox, meaning the attacker escapes Chrome's process isolation and runs code with the privileges of the browser on the host. All Chrome users running an unpatched version before 153.0.8010.36 are affected. As of now there is no public proof-of-concept and this specific flaw is not in CISA KEV, although the Chrome 153 release headlines reference a separate V8 zero-day that was exploited in the wild. Do: Update Google Chrome to 153.0.8010.36 or later immediately; Chrome 153 ships 230 security fixes, so unpatched installs are exposed to this and numerous other flaws. Verify the patched version fleet-wide (Help > About Chrome confirms and triggers the update), prioritize endpoints and users who browse untrusted websites, and note that the separately exploited V8 zero-day is also fixed in this release, raising the urgency of patching. | 9.6 | <1% |
| masson the order of billions of Chrome installs (Chrome has roughly 3 billion-plus users and majority global browser share; every install below 153.0.8010.36 is… |
Posted by Valtteri Vuorikoski on Sep 10 Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) The Chromium issue tracker link is restricted so further details are not available. While product is listed as Chrome by NIST, presumably this also affects Chromium and everything derived from it. Debian lists all current Chromium packages as...
This source does not provide full text. Read it at seclists.org.