CVE-2026-87578: Use After Free
Published Sep 9, 2026
·Updated
Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)
Affected Software
1 affected component
Google Google Chrome<153.0.8010.36
Event History
Sep 9, 2026
CVE Published
via MITRE·12:09 AM
Data Sourced
via MITRE·12:09 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must be adjacent to the target and able to deliver crafted network traffic. Successful exploitation can execute arbitrary code outside Chrome's sandbox.
2
Which Chrome versions need to be updated?
Google Chrome versions prior to 153.0.8010.36 are affected. Update Chrome to 153.0.8010.36 or later.