CVE-2026-87528: Critical severity Google Chrome vulnerability
Chromium CVE-2026-87528: Type confusion in Rust
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Type confusion in Rust in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.4234.32 - Upgrade
Upgrade
Google Chrome (Chromium-based) / Microsoft Edge (Chromium-based)to a version that resolves this vulnerability.Fixed in 153.0.8010.36 - Compensating control
Mitigate exposure by ensuring remote users cannot access vulnerable browser versions (e.g., block unpatched Chromium-based browsers or restrict browsing) until updated, since a crafted HTML page could allow potential arbitrary code execution outside the sandbox.
Event History
Frequently Asked Questions
Which deployments are affected?
Google Chrome on Windows is affected when the installed version is earlier than 153.0.8010.36.
What must an attacker do to trigger the issue?
The attacker needs to cause Chrome to process a crafted HTML page. The issue is described as remotely exploitable.
How can administrators determine whether remediation is needed?
Check the installed Chrome version on Windows. Systems running a version earlier than 153.0.8010.36 require an update.