From NIST NVD <https://nvd.nist.gov/vuln/detail/cve-2026-87464>: Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
The Chromium issue tracker link is restricted so further details are not available. While product is listed as Chrome by NIST, presumably this also affects Chromium and everything derived from it. Debian lists all current Chromium packages as vulnerable <https://security-tracker.debian.org/tracker/CVE-2026-87464>.
Related Gerrit for the linked Chromium issue 544163112: https://chromium-review.googlesource.com/c/angle/angle/+/8266365
-valtteri
Palo Alto Networks incorporated the following Chromium security fixes into our products:
https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop.html https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop29.html https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop8.html https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop.html
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.
Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Google Chromium-based browsers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Google Chromium-based browsers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 8.8.