Junglewise Threat Intelligence

CVE-2026-87524: Google Chrome use-after-free in Core on Windows

CVE-2026-87524 · Severity: high · CVSS 8.3 · Published 2026-09-09

Executive brief

Google Chrome on Windows contained a use-after-free vulnerability in its core rendering engine that could be exploited by an attacker who had already compromised the browser's renderer process. Successful exploitation could allow the attacker to escape the browser's security sandbox and execute arbitrary code on the user's computer, potentially leading to complete system compromise.

Technical details

This is a use-after-free vulnerability in Chrome's Core component affecting Windows systems prior to version 153.0.8010.36. The vulnerability could be triggered via a crafted HTML page and requires the attacker to have already compromised the renderer process (a sandboxed component responsible for executing web page code). Upon successful exploitation, the attacker can achieve sandbox escape and execute arbitrary code outside the sandbox with elevated privileges. The vulnerability was patched in Chrome 153.0.8010.36, released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released for Windows, Mac, and Linux

References

Related threats