Junglewise Threat Intelligence

CVE-2026-87504: Google Chrome use after free in Core via crafted extension

CVE-2026-87504 · Severity: critical · CVSS 9.6 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a use-after-free memory vulnerability in its Core component that allows attackers to execute arbitrary code outside the browser sandbox via a maliciously crafted Chrome extension paired with social engineering. An attacker could trick users into installing a malicious extension to gain access to system resources and run untrusted code with full system privileges, potentially leading to data theft, system compromise, and malware installation.

Technical details

The vulnerability is a use-after-free condition in Chrome's Core component that exists in versions prior to 153.0.8010.36. An attacker can craft a malicious Chrome extension that exploits this memory safety flaw to achieve arbitrary code execution outside the browser's sandboxing boundary. The attack requires social engineering to convince a user to install the extension, but once installed, the attacker gains access to unsandboxed privileges. The flaw has been patched in Chrome 153.0.8010.36 and later releases. Chromium rated this issue as Medium severity internally, though it was reported externally as critical due to the sandbox escape capability.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats