Junglewise Threat Intelligence

CVE-2026-87578: Google Chrome use-after-free in Receiver

CVE-2026-87578 · Severity: high · CVSS 8.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used by billions of users to access websites and web applications. This vulnerability allows an adjacent attacker on the same network to execute malicious code outside of Chrome's sandbox protection, potentially compromising the entire system and user data.

Technical details

A use-after-free vulnerability exists in the Receiver component of Google Chrome prior to version 153.0.8010.36. The vulnerability is triggered via crafted network traffic, requiring the attacker to be on an adjacent network (not direct internet access). An adjacent attacker can exploit this to achieve arbitrary code execution outside the sandbox, effectively bypassing Chrome's primary security boundary. The vulnerability was patched in Chrome 153.0.8010.36 released on September 8, 2026.

Affected products

  • Google Chrome Prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats