Junglewise Threat Intelligence

CVE-2026-87638: Google Chrome out of bounds write in Media

CVE-2026-87638 · Severity: critical · CVSS 9.6 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a memory safety vulnerability in its media handling component that allows attackers to write data outside allocated memory bounds. An attacker can exploit this flaw by sending a crafted HTML page to a user; if successful, the attacker could potentially escape Chrome's security sandbox and execute arbitrary code with the privileges of the user's browser process.

Technical details

This is an out-of-bounds write vulnerability in Google Chrome's Media component, affecting versions prior to 153.0.8010.36. The vulnerability allows a remote attacker to write data outside the bounds of allocated memory via a specially crafted HTML page. The attack is network-based and requires user interaction (visiting a malicious page), but does not require prior authentication. Exploitation could allow an attacker to execute arbitrary code outside the Chrome sandbox, potentially gaining full system access. The vulnerability was patched in Chrome 153.0.8010.36, released on September 8–9, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-08: disclosed: Chrome 153.0.8010.36 released with fix
  • 2026-09-09: advisory: CVE-2026-87638 published

References

Related threats