Junglewise Threat Intelligence

CVE-2026-87526: Google Chrome use-after-free in Passwords

CVE-2026-87526 · Severity: critical · CVSS 9.6 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's password management system contains a use-after-free memory vulnerability that allows remote attackers to execute arbitrary code outside the browser's security sandbox. Exploitation requires social engineering to trick a user into a specific interaction with the password manager UI. This could lead to complete compromise of browser processes and access to stored passwords and sensitive data.

Technical details

This vulnerability is a use-after-free flaw in Chrome's Passwords component, allowing remote code execution outside the sandbox via UI interaction. The attack vector requires social engineering and user interaction with the password manager interface. An attacker can leverage this to execute arbitrary code with the privileges of the Chrome process, bypassing the browser's sandbox protections. The vulnerability was patched in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36 and later

References

Related threats