CVE-2026-87602: Medium severity Google Google Chrome vulnerability
Chromium CVE-2026-87602: Out of bounds read in ANGLE
Other sources
Out of bounds read in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.4234.32 - Upgrade
Upgrade
Chromium-based (Google Chrome / Microsoft Edge) via ANGLEto a version that resolves this vulnerability.Fixed in 153.0.8010.36
Event History
Frequently Asked Questions
Which systems are affected?
The issue affects Google Chrome on Windows before version 153.0.8010.36. The vulnerability is in ANGLE, which Chrome uses on the affected platform.
What does an attacker need to exploit this issue?
An attacker would need to induce a user to load a crafted HTML page remotely. Successful exploitation could allow reading memory outside Chrome's sandbox.
Does the available information identify a workaround if updating is not immediately possible?
No workaround or mitigation is provided in the available information. Updating Chrome to version 153.0.8010.36 or later is the stated version boundary for the issue.