CVE-2026-87500: Out-of-bounds Read
Published Sep 9, 2026
·Updated
Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Affected Software
1 affected component
Google Chrome<153.0.8010.36
Event History
Sep 9, 2026
CVE Published
via MITRE·12:09 AM
Data Sourced
via MITRE·12:09 AM
DescriptionWeakness
Frequently Asked Questions
1
Who is exposed to this vulnerability?
Users of Google Chrome versions prior to 153.0.8010.36 are affected. Exploitation can occur remotely when a user visits a crafted HTML page.
2
What does an attacker need to exploit it?
The attacker needs to induce a target to load a crafted HTML page in a vulnerable Chrome version. No additional prerequisites are stated in the available information.
3
What is the impact of successful exploitation?
A successful exploit could allow arbitrary code execution outside Chrome's sandbox.