Executive brief
Google Chrome's extension system contains a flaw in how it resolves references, allowing a remote attacker to potentially execute malicious code outside the browser sandbox. This could allow attackers to compromise user systems, steal data, or install malware with full system privileges. The vulnerability affects Chrome versions prior to 153.0.8010.36.
Technical details
The vulnerability is an incorrect reference resolution flaw in Google Chrome's extension handling mechanism. A remote attacker can exploit this via crafted network traffic to execute arbitrary code that escapes the sandbox protection, bypassing Chrome's security isolation. The vulnerability requires no user authentication but does require the victim to be exposed to malicious network traffic or a specially crafted web page. A fix was released in Chrome version 153.0.8010.36 and later. The Chromium security team rated this as "Medium" severity internally, though external sources assigned a critical rating.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed: CVE-2026-87613 disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36