Junglewise Threat Intelligence

CVE-2026-87455: Google Chrome use-after-free in Aura

CVE-2026-87455 · Severity: critical · CVSS 9.6 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a use-after-free vulnerability in its Aura window management component that allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page. This could enable complete compromise of user systems, including data theft, malware installation, and account hijacking. The vulnerability affects Chrome versions prior to 153.0.8010.36 and is classified as critical severity.

Technical details

A use-after-free memory safety vulnerability exists in the Aura component of Google Chrome. The vulnerability can be triggered by a remote attacker through a crafted HTML page, allowing code execution outside the Chrome sandbox. The attack requires only network reachability (delivery of a malicious webpage) and no user authentication; however, user interaction (visiting the malicious page) is necessary to trigger the flaw. Successful exploitation results in arbitrary code execution with user privileges, potentially granting full system compromise. The fix is available in Chrome version 153.0.8010.36 and later.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats