CVE-2026-87628: Use After Free
Published Sep 9, 2026
·Updated
Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)
Affected Software
1 affected component
Google Chrome<153.0.8010.36
Event History
Sep 9, 2026
CVE Published
via MITRE·12:09 AM
Data Sourced
via MITRE·12:09 AM
DescriptionWeakness
Frequently Asked Questions
1
Who is realistically exposed to this vulnerability?
Chrome users running versions earlier than 153.0.8010.36 are affected. Exploitation requires an adjacent attacker able to deliver crafted network traffic.
2
What level of access could successful exploitation provide?
A successful attack could potentially allow arbitrary code execution outside Chrome's sandbox.
3
How can I determine whether remediation is needed?
Check the installed Google Chrome version. Systems running a version earlier than 153.0.8010.36 require an update.