CVE-2026-87654: Buffer Overflow
Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Other sources
Chromium CVE-2026-87654: Buffer overflow in ANGLE
— Microsoft
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.4234.32 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.8010.36 - Compensating control
Mitigate risk by preventing remote attackers from reaching browsers with crafted HTML until patched—e.g., restrict access to untrusted web content via browser/site isolation, web filtering, or restricting outbound browsing to trusted domains.
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Google Chrome on Windows is affected when running a version earlier than 153.0.8010.36. The provided information does not identify impact on other operating systems.
What does an attacker need to exploit it?
An attacker needs to cause a user to load a crafted HTML page remotely. Successful exploitation can result in arbitrary code execution outside the Chrome sandbox.
What is the remediation?
Update Google Chrome on Windows to version 153.0.8010.36 or later.