Executive brief
Google Chrome on Windows contains a use-after-free memory vulnerability in its ANGLE graphics component. An attacker who has already compromised Chrome's renderer process can exploit this flaw via a crafted web page to execute arbitrary code outside the browser's security sandbox, potentially gaining full system access.
Technical details
This is a use-after-free vulnerability in ANGLE (Almost Native Graphics Layer Engine), Google Chrome's graphics abstraction layer on Windows. The vulnerability allows a remote attacker who has already compromised the renderer process to execute arbitrary code outside the sandbox via a specially crafted HTML page. The attack requires prior renderer process compromise and network delivery of malicious content. Google patched this vulnerability in Chrome 153.0.8010.36 and later versions. The Chromium security team rated the vulnerability as Medium severity internally, though external assessment is higher.
Affected products
- Google Chrome prior to 153.0.8010.36 on Windows
Timeline
- 2026-09-09: disclosed: CVE-2026-87648 published
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36