Junglewise Threat Intelligence

CVE-2026-87464: Google Chrome use-after-free in WebGL

CVE-2026-87464 · Severity: critical · CVSS 9.6 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a use-after-free vulnerability in its WebGL graphics rendering component that allows attackers to execute arbitrary code outside the browser sandbox by tricking users into visiting a malicious webpage. A successful exploit could lead to complete system compromise, including theft of sensitive data, installation of malware, or remote control of the user's computer.

Technical details

A use-after-free memory corruption vulnerability exists in the WebGL component of Google Chrome prior to version 153.0.8010.36. The vulnerability allows a remote attacker to execute arbitrary code with privileges outside the sandbox by crafting a malicious HTML page that triggers the flaw. The attack requires only that a user visits the malicious webpage; no additional user interaction or prior authentication is needed. An attacker exploiting this flaw can escape the browser sandbox and achieve code execution on the underlying system. This vulnerability has been patched in Chrome version 153.0.8010.36 and later.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats