Junglewise Threat Intelligence

CVE-2026-87480: Google Chrome use-after-free in Printing component

CVE-2026-87480 · Severity: high · CVSS 8.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used by billions of people worldwide. A use-after-free vulnerability in the printing module allows a remote attacker to escape the browser's security sandbox and potentially execute arbitrary code on a victim's computer if they visit a specially crafted webpage. This could lead to full system compromise, malware installation, or theft of sensitive user data.

Technical details

A use-after-free vulnerability exists in Google Chrome's Printing component, affecting versions prior to 153.0.8010.36. The vulnerability requires that an attacker has already compromised the renderer process; from this position, a crafted HTML page can trigger the use-after-free condition and break out of the sandbox to achieve arbitrary code execution outside the sandbox. The attack vector is network-based via a malicious webpage. The vulnerability was patched in Chrome 153.0.8010.36 released on September 9, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed: Public disclosure via Chrome security page and NVD
  • 2026-09-09: patched: Fix released in Chrome 153.0.8010.36 for Windows, Mac, and Linux

References

Related threats