Junglewise Threat Intelligence

CVE-2026-87637: Google Chrome use-after-free in Extensions on Mac

CVE-2026-87637 · Severity: critical · CVSS 9.6 · Published 2026-09-09

Executive brief

Google Chrome is a web browser used by hundreds of millions of people worldwide to access websites and web applications. A vulnerability in the Extensions component allows a remote attacker to execute malicious code outside Chrome's security sandbox via a specially crafted webpage, potentially giving attackers full control of an affected user's computer and access to all stored passwords, files, and personal data.

Technical details

This is a use-after-free vulnerability in the Extensions component of Google Chrome on macOS. A remote attacker can exploit this flaw by crafting a malicious HTML page that, when visited by a user, triggers the use-after-free condition and achieves arbitrary code execution outside the Chrome sandbox. The vulnerability affects Chrome versions prior to 153.0.8010.36/37 and was patched in that release. Exploitation does not require prior authentication or user interaction beyond visiting the malicious page.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats