Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 6.4 Browsers CVE-2026-87654 CVE-2026-87638 CVE-2026-87547 CVE-2026-87474

Google Chrome Stable Update Fixes Eight Vulnerabilities, Several Allowing Code Execution

Google has released a Chrome Stable update to version 153.0.8010.36 fixing eight vulnerabilities, including several use-after-free, buffer overflow, and type confusion flaws that could allow remote code execution via crafted web pages.

AI summary

Google has published a Stable channel update for Chrome on desktop, addressing eight distinct vulnerabilities across various browser components including V8, Media, FileSystem, Extensions, Input handling, and FileAPI. The update is documented in the Chrome Releases blog and cross-referenced in the National Vulnerability Database (NVD). All eight issues are fixed in Chrome version 153.0.8010.36.

Overview of the fixed vulnerabilities

Google's Chrome Stable channel update addresses eight separate CVEs: CVE-2026-87654 (buffer overflow in ANGLE, Windows-specific), CVE-2026-87638 (out of bounds write in Media), CVE-2026-87547 (incorrect reference resolution in FileSystem), CVE-2026-87474 (use after free in Payments), CVE-2026-87613 (incorrect reference resolution in Extensions), CVE-2026-87612 (type confusion in V8), CVE-2026-87542 (use after free in Input), and CVE-2026-87433 (race condition in FileAPI). Several of these are classified by Chromium's internal severity rating as High; others as Medium.

Root causes vary by component

The vulnerabilities stem from different underlying weakness classes: buffer overflow (CWE-122) in CVE-2026-87654; out of bounds write (CWE-787) in CVE-2026-87638; incorrect reference resolution (CWE-706) in both CVE-2026-87547 and CVE-2026-87613; use after free (CWE-416) in both CVE-2026-87474 and CVE-2026-87542; type confusion (CWE-843) in CVE-2026-87612; and a race condition (CWE-367) in CVE-2026-87433. Most descriptions indicate exploitation via a crafted HTML page; CVE-2026-87613 instead references crafted network traffic.

Potential for sandbox escape and code execution

Several of the vulnerabilities (CVE-2026-87654, CVE-2026-87638, CVE-2026-87547, CVE-2026-87474, CVE-2026-87613) are described as potentially allowing a remote attacker to execute arbitrary code outside the Chrome sandbox, which would represent a significant compromise of the host system beyond the browser process itself. CVE-2026-87612 and CVE-2026-87542 describe code execution inside the sandbox, which is a lesser but still serious impact. CVE-2026-87433 describes a site isolation bypass requiring prior renderer compromise, making it a secondary-stage issue rather than an initial-access vector.

Affected users

All users running Google Chrome on desktop prior to version 153.0.8010.36 are affected. CVE-2026-87654 is specifically noted as affecting the Windows build of Chrome; the other seven vulnerabilities are not described as platform-specific in the available facts.

Affected and fixed versions

All eight vulnerabilities affect Google Chrome versions prior to 153.0.8010.36. No earlier affected version boundary is specified in the available data. The fix for all eight issues is included in Chrome 153.0.8010.36.

Fix available

Google has released Chrome 153.0.8010.36 for desktop, which resolves all eight vulnerabilities described in this briefing. No workaround is documented; updating to the fixed version is the remediation path confirmed by the vendor source.

What to do

Update Google Chrome to version 153.0.8010.36 or later as soon as possible. Chrome typically updates automatically on restart, but administrators managing fleets of browsers should verify that the update has been applied, particularly given the number of high-severity issues addressed in this release.

PatchBriefing score

6.4 / 10 · Medium

Official CVSS: 9.6

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Why this score

This briefing covers eight CVEs with individual patchwire scores ranging from 5.9 to 6.4. The highest-scored issues (CVE-2026-87654, CVE-2026-87638, CVE-2026-87547, CVE-2026-87474) carry a CVSS base score of 9.6, reflecting network attack vector, low complexity, no privileges required, and high confidentiality/integrity/availability impact with a scope change (sandbox escape). CVE-2026-87613 scores 9.0 CVSS with high attack complexity but no user interaction required. CVE-2026-87612, CVE-2026-87542, and CVE-2026-87433 score 8.8 CVSS, reflecting similar impact without the scope-changing sandbox escape. None of the eight vulnerabilities are currently flagged as known exploited, associated with ransomware campaigns, or having public exploit code, which keeps the computed patchwire scores in the moderate range despite high CVSS values.

Affected versions

≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched

Reported fixes

Google has released Chrome 153.0.8010.36 for desktop, which resolves all eight vulnerabilities described in this briefing. No workaround is documented; updating to the fixed version is the remediation path confirmed by the vendor source.

How this was built

9 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome Stable Update Fixes Eight Vulnerabilities, Several Allowing Code Execution
1 article · 9 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email