Junglewise Threat Intelligence

CVE-2026-87467: Google Chrome race condition in Updater on Windows

CVE-2026-87467 · Severity: high · CVSS 8.1 · Published 2026-09-09

Executive brief

Google Chrome's automatic update component on Windows contains a race condition vulnerability that allows a local attacker with access to the system to execute arbitrary code outside the browser's security sandbox. This could allow an attacker to fully compromise the computer and access sensitive data or install malware with system-level privileges.

Technical details

A race condition exists in the Updater component of Google Chrome on Windows prior to version 153.0.8010.36. The vulnerability allows a local attacker to potentially execute arbitrary code outside the Chrome sandbox via a local program, exploiting a timing window in the update process. The attack requires local access to the system but no user interaction is needed to trigger the vulnerability. No public exploit code has been reported. The vulnerability is fixed in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats