Executive brief
Google Chrome's V8 JavaScript engine contains a use-after-free vulnerability that allows attackers to execute arbitrary code within the browser sandbox by crafting a malicious HTML page. This could enable code execution on a user's system when visiting a compromised or attacker-controlled website, potentially compromising user data and system security.
Technical details
A use-after-free vulnerability exists in Google Chrome's V8 JavaScript engine (CVE-2026-87536) that allows remote code execution within the sandbox. The vulnerability can be triggered by sending a crafted HTML page to a victim user; no authentication or special user interaction beyond visiting a malicious webpage is required. An attacker exploiting this flaw can execute arbitrary code with the privileges of the renderer process within Chrome's sandbox, potentially leading to information disclosure or further exploitation. The vulnerability has been patched in Chrome version 153.0.8010.36 and later.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36
- 2026-09-09: disclosed: Published in NVD