Junglewise Threat Intelligence

CVE-2026-87572: Google Chrome injection in DevTools via crafted HTML

CVE-2026-87572 · Severity: high · CVSS 8.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Developer Tools component contains an injection vulnerability that allows remote attackers to execute arbitrary code outside the sandbox. An attacker who has already compromised Chrome's renderer process can craft a malicious HTML page to escape browser isolation, potentially leading to full system compromise. This bypasses Chrome's core security sandbox that normally contains web content.

Technical details

This vulnerability is a code injection flaw in Chrome's DevTools component that allows sandbox escape. The attack requires the attacker to have already compromised the renderer process, meaning a prior vulnerability (such as a WebGL bug) would typically be chained with this flaw to achieve full exploitation. An attacker can craft a specially designed HTML page to inject and execute arbitrary code outside the sandbox boundary, breaking Chrome's process isolation model. The vulnerability was fixed in Chrome version 153.0.8010.36 released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats