- Description
- Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- Source
- chrome-cve-admin@google.com
- NVD status
- Modified
- Products
- chrome
CVSS 3.1
- Type
- Secondary
- Base score
- 9.6
- Impact score
- 6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- chrome-cve-admin@google.com
- CWE-416
- Hype score
- Not currently trending
CVE-2026-87491, an out-of-bounds write in V8, was exploited in the wild for remote code execution inside the Chrome sandbox. Google shipped the fix in 153.0.8010.36. The same update closed 229 additional issues, including CVE-2026-87464, CVE-2026-87488, CVE-2026-87438,
@SecureChap
9 Sept 2026
75 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
@Google ships Chrome 153 fixing 230 vulnerabilities, including five critical issues and one actively exploited zero-day. The update resolves use-after-free flaws in WebGL (CVE-2026-87464, CVE-2026-87488), an out-of-bounds write in V8 (CVE-2026-87491) already seen in attacks,
@WorldCyberNewsX
9 Sept 2026
12 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7BC1B89D-DEB1-48BD-8602-0869B89600FD",
"versionEndExcluding": "153.0.8010.36",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]