Junglewise Threat Intelligence

CVE-2026-87529: Google Chrome numeric truncation in Media

CVE-2026-87529 · Severity: critical · CVSS 9.6 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome processes video and audio content through its Media component, which is core to web browsing. A numeric truncation error in this component could allow an attacker to escape Chrome's security sandbox and run malicious code directly on a user's computer via a specially crafted webpage.

Technical details

A numeric truncation error in the Media component of Google Chrome prior to version 153.0.8010.36 allows remote code execution outside the sandbox. The vulnerability is triggered by processing a crafted HTML page containing malicious media content. No authentication or user interaction beyond visiting a webpage is required for exploitation. An attacker can achieve arbitrary code execution with full system privileges by escaping the browser's sandbox protection, which normally restricts web content from accessing the operating system.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released for Windows, Mac, and Linux

References

Related threats