Junglewise Threat Intelligence

CVE-2026-87639: Google Chrome use after free in WebPackaging

CVE-2026-87639 · Severity: high · CVSS 8.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a use-after-free vulnerability in its WebPackaging component that could allow an attacker who has compromised the renderer process to execute arbitrary code outside the sandbox. An attacker would need to trick a user into visiting a specially crafted HTML page after first compromising the renderer. Successful exploitation could lead to complete system compromise and arbitrary code execution with elevated privileges.

Technical details

A use-after-free vulnerability exists in the WebPackaging component of Google Chrome prior to version 153.0.8010.36. The vulnerability allows a remote attacker who has already compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. The attack requires prior renderer process compromise and user interaction (visiting a malicious page). The vulnerability has been fixed in Chrome 153.0.8010.36 and later versions. The Chromium security team classified this as a High severity issue (CVSS 8.3).

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats