CVE-2026-87525: Low severity Google Google Chrome vulnerability
Chromium CVE-2026-87525: Out of bounds read in Chromoting
Other sources
Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read memory outside the sandbox via a local program. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.4234.32 - Upgrade
Upgrade
Google Chrome/Chromium (Chromoting)to a version that resolves this vulnerability.Fixed in 153.0.8010.36 - Compensating control
Because the bug is in Chromoting, limit access to Chromoting to trusted users and prevent untrusted local programs from launching or interacting with it.
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
The issue affects Google Chrome on Windows before version 153.0.8010.36. Exploitation requires a local attacker using a local program.
What access does an attacker need to exploit it?
An attacker needs local access sufficient to run a program on the affected Windows system. The reported impact is reading memory outside the Chrome sandbox.
How can I remediate the issue?
Update Google Chrome on Windows to version 153.0.8010.36 or later.