Junglewise Threat Intelligence

CVE-2026-87601: Google Chrome race condition in V8 sandbox escape

CVE-2026-87601 · Severity: high · CVSS 7.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's V8 JavaScript engine contains a race condition that allows an attacker to break out of the browser's security sandbox and execute arbitrary code on the user's machine. A user visiting a malicious webpage could be compromised without any further interaction, leading to data theft, malware installation, or complete system compromise.

Technical details

A race condition exists in the V8 JavaScript engine used by Google Chrome, allowing remote code execution outside the browser sandbox. The vulnerability can be exploited via a crafted HTML page delivered over the network; no user authentication or interaction beyond visiting a malicious website is required. An attacker can achieve arbitrary code execution with the privileges of the user running Chrome, potentially gaining full system access. The vulnerability was patched in Chrome 153.0.8010.36, released in September 2026; users should update immediately.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats