Junglewise Threat Intelligence

CVE-2026-87625: Google Chrome use after free in V8

CVE-2026-87625 · Severity: high · CVSS 8.8 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used by billions of people to access websites and web applications. A use-after-free vulnerability in Chrome's V8 JavaScript engine allows an attacker to execute arbitrary code within the browser's sandbox by tricking users into installing a malicious Chrome extension. Exploitation could lead to unauthorized access to user data or lateral movement to other systems.

Technical details

This is a use-after-free vulnerability in V8, Google Chrome's JavaScript engine, present in versions prior to 153.0.8010.36. The vulnerability can be triggered via a crafted Chrome extension, which requires user interaction (installation). The attack vector is social engineering—convincing a user to install a malicious extension. Successful exploitation allows an attacker to execute arbitrary code within the browser sandbox. The vulnerability is patched in Chrome 153.0.8010.36 and later versions. While marked as Medium severity by Chromium, it carries higher CVSS scoring (8.8) due to the code execution impact, though containment within the sandbox limits full system compromise.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats