CVE-2026-87625: Use After Free
Chromium CVE-2026-87625: Use after free in V8
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.4234.32 - Upgrade
Upgrade
Google Chrome / Chromium-based browsers (V8)to a version that resolves this vulnerability.Fixed in 153.0.8010.36 - Compensating control
Mitigate social-engineering risk by limiting extension installation to trusted sources/users until the browser is updated to 153.0.8010.36 (Chromium-based browsers ingest the Chromium fix).
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
The attacker needs to persuade a user to interact with or install a crafted Chrome extension. Successful exploitation enables arbitrary code execution inside Chrome's sandbox.
Which Chrome versions should be considered affected?
Google Chrome versions earlier than 153.0.8010.36 are affected. Update Chrome to 153.0.8010.36 or later.
Who is most exposed if updates cannot be applied immediately?
Users who can be socially engineered into using a malicious or crafted Chrome extension are the relevant exposure group. Until Chrome is updated, avoid installing or interacting with untrusted extensions.