CVE-2026-87578: Google Chrome

High severity, CVSS 8.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)

Affected products

  • Google Chrome: before 153.0.8010.36 (fixed in 153.0.8010.36)

Published 2026-09-09. Last modified 2026-09-10.