Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.9 Browsers CVE-2026-87636 CVE-2026-87579 CVE-2026-87536 CVE-2026-87588

Google Chrome Stable Update Fixes Seven High-Severity Memory Safety Vulnerabilities

Google has released Chrome 153.0.8010.36 for desktop, fixing seven high-severity memory safety vulnerabilities (CVE-2026-87636, CVE-2026-87579, CVE-2026-87536, CVE-2026-87588, CVE-2026-87444, CVE-2026-87585, CVE-2026-87587) that could allow remote code execution inside the browser sandbox via crafted web pages or PDF files.

AI summary

Google has shipped a Stable Channel update for Chrome on desktop that addresses seven separate memory safety vulnerabilities across multiple browser components. All seven issues share the same CVSS base score of 8.8 and could allow a remote attacker to execute arbitrary code inside Chrome's sandbox if a user visits a maliciously crafted web page or, in one case, opens a crafted PDF file. The fixes are consolidated in version 153.0.8010.36.

Seven memory safety bugs fixed in one release

Google's Chrome Stable Channel update for desktop fixes seven distinct vulnerabilities, each tracked under its own CVE: CVE-2026-87636 (type confusion in XML), CVE-2026-87579 (buffer overflow in WebRTC), CVE-2026-87536 (use after free in V8), CVE-2026-87588 (use after free in Chromecast), CVE-2026-87444 (memory corruption in Codecs), CVE-2026-87585 (double free in PDFium, Windows only), and CVE-2026-87587 (use after free in V8). All are rated CVSS 3.1 base score 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Chromium internally rates CVE-2026-87536, CVE-2026-87444, CVE-2026-87585, and CVE-2026-87587 as 'High' severity, and CVE-2026-87636, CVE-2026-87579, and CVE-2026-87588 as 'Medium' severity.

Underlying weaknesses: use-after-free, buffer overflow, type confusion, and double free

The vulnerabilities stem from different classes of memory safety defects: use-after-free conditions (CVE-2026-87536 and CVE-2026-87587 in V8, CVE-2026-87588 in Chromecast), a buffer overflow in WebRTC (CVE-2026-87579), a type confusion in XML handling (CVE-2026-87636), memory corruption in the Codecs component (CVE-2026-87444), and a double-free in the PDFium library on Windows (CVE-2026-87585). Each can be triggered by a crafted HTML page, and CVE-2026-87585 specifically via a crafted PDF file.

Potential for sandboxed remote code execution

All seven vulnerabilities could allow a remote attacker to execute arbitrary code inside Chrome's sandbox. While sandbox containment limits the immediate impact, successful exploitation of memory corruption bugs in core rendering and processing components (V8, WebRTC, PDFium, Codecs, XML, Chromecast) can serve as a foothold for further attacks, including sandbox escape chains if combined with other vulnerabilities. Exploitation requires user interaction, such as visiting a malicious page or opening a malicious PDF.

Who is affected

All users running Google Chrome on desktop prior to version 153.0.8010.36 are affected. CVE-2026-87585 (PDFium double-free) specifically affects Chrome on Windows. The other six vulnerabilities are not described as platform-specific in the available source material.

Affected and fixed versions

Chrome versions prior to 153.0.8010.36 are affected by all seven vulnerabilities. The fix is included in Chrome 153.0.8010.36 for desktop.

Fix available in Chrome 153.0.8010.36

Google has released Chrome 153.0.8010.36 for desktop, which contains fixes for all seven vulnerabilities described in this briefing. No workarounds or mitigations beyond updating are mentioned in the source material.

Update Chrome now

Site owners and users should ensure Chrome is updated to version 153.0.8010.36 or later. Chrome typically updates automatically on restart; users can manually trigger an update check via Settings > About Chrome. No exploitation in the wild or public proof-of-concept exploit has been reported for any of these vulnerabilities at the time of this briefing.

PatchBriefing score

5.9 / 10 · Medium

Official CVSS: 8.8

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Why this score

Each of the seven vulnerabilities carries a patchwire_score of 5.9, driven primarily by a CVSS 3.1 base score of 8.8 (network attack vector, low complexity, no privileges required, but user interaction required, with high impact to confidentiality, integrity, and availability). Additional contribution comes from the unauthenticated remote attack vector and Chrome's extremely high product popularity (estimated install base of 1 billion+). The score factors indicate no known exploitation in the wild, no public exploit code, and no EPSS data available for any of these CVEs, which keeps the score from reaching the highest severity tiers despite the high CVSS base score.

Affected versions

≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched

Reported fixes

Google has released Chrome 153.0.8010.36 for desktop, which contains fixes for all seven vulnerabilities described in this briefing. No workarounds or mitigations beyond updating are mentioned in the source material.

How this was built

8 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome Stable Update Fixes Seven High-Severity Memory Safety Vulnerabilities
1 article · 8 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email