CVE-2026-87444: Buffer Overflow
Chromium CVE-2026-87444: Memory corruption in Codecs
Other sources
Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.4234.32 - Upgrade
Upgrade
Google Chrome / Chromium (as used by Microsoft Edge)to a version that resolves this vulnerability.Fixed in 153.0.8010.36
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs to induce a user to load a crafted HTML page. Successful exploitation can execute arbitrary code inside the Chrome sandbox.
Which Chrome versions are affected?
Google Chrome versions prior to 153.0.8010.36 are affected.
Does exploitation escape the Chrome sandbox?
The provided information states that arbitrary code execution occurs inside the sandbox. It does not indicate that this vulnerability alone enables a sandbox escape.