Junglewise Threat Intelligence

CVE-2026-87628: Google Chrome use-after-free in Cast

CVE-2026-87628 · Severity: high · CVSS 8.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Cast functionality contains a memory safety flaw that can be exploited by a nearby attacker to execute malicious code outside the sandbox, potentially compromising user systems. An attacker could deliver crafted network packets to trigger this vulnerability, gaining the ability to bypass Chrome's security isolation and run arbitrary code with elevated privileges.

Technical details

A use-after-free vulnerability exists in the Cast component of Google Chrome versions prior to 153.0.8010.36. The flaw allows an adjacent network attacker to craft specially formatted network traffic that triggers memory safety errors, enabling arbitrary code execution outside the Chrome sandbox. The vulnerability requires network proximity but no user interaction or authentication. When exploited, an attacker can completely break out of the browser's security sandbox and execute arbitrary code with full system access. The fix is available in Chrome 153.0.8010.36 and later releases.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed: CVE-2026-87628 published by NVD
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36
  • 2026-08-28: other: Vulnerability reported to Google by Hafiizh

References

Related threats