Junglewise Threat Intelligence

CVE-2026-87512: Google Chrome use-after-free in ANGLE on Windows

CVE-2026-87512 · Severity: critical · CVSS 9.6 · Published 2026-09-09

Executive brief

Google Chrome, a widely used web browser, contains a memory safety vulnerability in its ANGLE graphics component that affects Windows systems. An attacker can exploit this through a crafted web page to execute arbitrary code outside the browser's security sandbox, potentially compromising the entire system and accessing sensitive user data.

Technical details

A use-after-free vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome on Windows prior to version 153.0.8010.36. The vulnerability allows a remote attacker to craft a malicious HTML page that, when visited, exploits the memory safety flaw to execute arbitrary code with privileges outside the browser sandbox. The attack requires only that a user visit a malicious webpage and does not require authentication or prior system access. The vulnerability was patched in Chrome 153.0.8010.36 released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36 on Windows

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats