Junglewise Threat Intelligence

CVE-2026-87581: Google Chrome use-after-free in Payments component

CVE-2026-87581 · Severity: critical · CVSS 9.6 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a use-after-free vulnerability in its Payments processing component that can be exploited through a crafted web page. An attacker could leverage social engineering to trick a user into visiting a malicious site, potentially allowing code execution outside the browser sandbox and compromising the security of the entire system.

Technical details

A use-after-free vulnerability exists in Google Chrome's Payments component (prior to version 153.0.8010.36) that allows remote code execution outside the sandbox. The vulnerability is triggered through a crafted HTML page and requires social engineering to convince a user to visit the malicious site. The attack is network-based and does not require prior authentication. Successful exploitation grants an attacker arbitrary code execution with the same privileges as the user running the browser. The vulnerability was patched in Chrome 153.0.8010.36, released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed: CVE-2026-87581 disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released with fix

References

Related threats