Junglewise Threat Intelligence

CVE-2026-87558: Google Chrome use after free in Payments on Mac

CVE-2026-87558 · Severity: critical · CVSS 9.6 · Published 2026-09-09

Technologies: Apple macOS, Google Chrome. Vendors: Apple, Google.

Executive brief

Google Chrome for macOS contained a use-after-free vulnerability in its Payments component that allowed attackers to execute arbitrary code outside the browser sandbox via a crafted HTML page. This could enable an attacker to fully compromise a user's system, bypass Chrome's security protections, and gain access to sensitive data or install malware.

Technical details

The vulnerability is a use-after-free bug in the Payments component of Google Chrome on macOS prior to version 153.0.8010.36. The flaw allows a remote attacker to execute arbitrary code outside the sandbox boundary by providing a specially crafted HTML page that triggers the memory corruption. Use-after-free vulnerabilities occur when freed memory is accessed again, potentially allowing control of program execution. No special authentication or user interaction beyond visiting a malicious webpage is required. The vulnerability was patched in Chrome 153.0.8010.36 released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36 on Mac

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36

References

Related threats