CVE-2026-87533: Use After Free
Chromium CVE-2026-87533: Use after free in DevTools
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.4234.32 - Upgrade
Upgrade
Google Chrome / Chromium (DevTools)to a version that resolves this vulnerability.Fixed in 153.0.8010.36 - Upgrade
Upgrade
Microsoft Edge (Chromium-based) / DevToolsto a version that resolves this vulnerability.Fixed in 153.0.8010.36
Event History
Frequently Asked Questions
Who is exposed to this issue?
The issue affects Google Chrome versions prior to 153.0.8010.36. Exploitation requires a local attacker and a local program.
What level of access does an attacker need?
An attacker must be able to run a program locally on the affected system. The vulnerability could allow that local attacker to execute arbitrary code outside Chrome's sandbox.
What version addresses the issue?
Chrome 153.0.8010.36 addresses the issue; versions earlier than that are affected.