Executive brief
Google Chrome on macOS contained a memory safety vulnerability that could allow an attacker to execute malicious code outside the browser's security sandbox by tricking a user into visiting a crafted webpage. This could lead to complete system compromise, theft of user data, or unauthorized access to sensitive information stored on the device.
Technical details
This is a use-after-free vulnerability in the Device component of Google Chrome on macOS, where memory is accessed after it has been freed, allowing attackers to corrupt the heap and gain code execution. The vulnerability is triggered through a malicious HTML page delivered over the network; no authentication or elevated privileges are required. An attacker can exploit this to execute arbitrary code outside Chrome's sandbox, bypassing the browser's primary isolation mechanism. The vulnerability was patched in Chrome version 153.0.8010.36 released on September 8, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36 on Mac
Timeline
- 2026-09-09: disclosed: CVE-2026-87607 disclosure
- 2026-09-08: patched: Chrome 153.0.8010.36 released to stable channel