CVE-2026-87647: Google Chrome vulnerability
Published Sep 9, 2026
·Updated
Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Affected Software
1 affected component
Google Chrome<153.0.8010.36
Event History
Sep 9, 2026
CVE Published
via MITRE·12:09 AM
Data Sourced
via MITRE·12:09 AM
DescriptionWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must already have compromised the Chrome renderer process. The crafted HTML page is used to trigger the GPU flaw after that compromise.
2
What is the security impact after successful exploitation?
A successful attacker can read memory outside the renderer sandbox. The issue is described as an uninitialized resource vulnerability in the GPU.
3
Which Chrome versions are affected?
Google Chrome versions prior to 153.0.8010.36 are affected.