Junglewise Threat Intelligence

CVE-2026-87587: Google Chrome use-after-free in V8

CVE-2026-87587 · Severity: high · CVSS 8.8 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's V8 JavaScript engine contained a use-after-free memory vulnerability that could allow an attacker to execute arbitrary code within the browser's sandbox by serving a malicious HTML page. This could lead to browser compromise, session hijacking, or lateral movement to other systems on the user's network.

Technical details

A use-after-free vulnerability exists in V8 (Chrome's JavaScript engine) in Chrome versions prior to 153.0.8010.36. The vulnerability can be triggered remotely via a crafted HTML page delivered over the network without requiring user authentication or special privileges. An attacker can exploit this to execute arbitrary code within the Chrome sandbox environment. While sandboxing limits direct system compromise, sandbox escapes are possible, making this a significant attack vector. The vulnerability has been patched in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed: Published on NVD
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats