CVE-2026-87634: Use After Free
Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Users running Google Chrome versions earlier than 153.0.8010.36 may be exposed if they visit a crafted HTML page.
What does an attacker need to exploit it?
The vulnerability is remotely exploitable through a crafted HTML page. The available information does not state that authentication, local access, or user interaction beyond loading the page is required.
What is the security impact if exploitation succeeds?
A successful exploit could potentially allow arbitrary code execution outside Chrome's sandbox.
How can I determine whether a system is affected?
Check the installed Google Chrome version. Versions prior to 153.0.8010.36 are affected according to the available information.