Junglewise Threat Intelligence

CVE-2026-87474: Google Chrome use-after-free in Payments

CVE-2026-87474 · Severity: critical · CVSS 9.6 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Payments component contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code outside the browser sandbox through a specially crafted webpage. This could enable attackers to gain full system access, steal sensitive data, or install malware on users' computers.

Technical details

The vulnerability is a use-after-free flaw in the Payments component of Google Chrome prior to version 153.0.8010.36. The attack requires no user authentication or special privileges—an attacker can trigger the vulnerability by hosting a malicious HTML page and convincing a user to visit it. Upon successful exploitation, the attacker can break out of Chrome's sandbox security model and execute arbitrary code with the privileges of the logged-in user. Google has patched this issue in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats