CVE-2026-87628: Critical Use after free in Cast
Chromium CVE-2026-87628: Use after free in Cast
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.4234.32 - Upgrade
Upgrade
Google Chrome / Chromium (Cast)to a version that resolves this vulnerability.Fixed in 153.0.8010.36 - Compensating control
Since exploitation is possible via crafted network traffic, restrict network access to untrusted sources (e.g., via firewall/ACL) until Chromium/Chrome is updated.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
Who is realistically exposed to this vulnerability?
Chrome users running versions earlier than 153.0.8010.36 are affected. Exploitation requires an adjacent attacker able to deliver crafted network traffic.
What level of access could successful exploitation provide?
A successful attack could potentially allow arbitrary code execution outside Chrome's sandbox.
How can I determine whether remediation is needed?
Check the installed Google Chrome version. Systems running a version earlier than 153.0.8010.36 require an update.