Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 6.4 Browsers CVE-2026-87512 CVE-2026-87528 CVE-2026-87637 CVE-2026-87643

Google Chrome Stable Update Fixes Eight High-Severity Memory Safety Vulnerabilities

Google has released Chrome 153.0.8010.36 for desktop, fixing eight vulnerabilities including use-after-free, type confusion, buffer overflow, and integer overflow issues across components such as ANGLE, Extensions, GPU, WebGL, DevTools, and Payments. All carry a CVSS score of 9.6.

AI summary

Google has published a Stable Channel update for Chrome on desktop, addressing eight distinct vulnerabilities disclosed on the same day. The flaws span several Chrome components — including the ANGLE graphics layer, the Rust codebase, Extensions, GPU handling, WebGL, DevTools, and the Payments feature — and were each assigned a CVSS base score of 9.6. The update is available as version 153.0.8010.36.

Eight vulnerabilities patched in one update

Chrome's Stable Channel update released on September 8, 2026 addresses eight separate CVEs: CVE-2026-87512 (use-after-free in ANGLE), CVE-2026-87528 (type confusion in Rust), CVE-2026-87637 (use-after-free in Extensions), CVE-2026-87643 (integer overflow in GPU), CVE-2026-87527 (buffer overflow in WebGL), CVE-2026-87448 (use-after-free in DevTools), CVE-2026-87558 (use-after-free in Payments), and CVE-2026-87581 (use-after-free in Payments). Each advisory describes exploitation via a crafted HTML page.

Memory safety issues across multiple components

The vulnerabilities stem from distinct root causes: use-after-free conditions (CWE-416) affect ANGLE, Extensions, DevTools, and Payments (two separate instances); a type confusion issue (CWE-843) affects Rust code; a buffer overflow (CWE-122) affects WebGL; and an integer overflow (CWE-190) affects GPU handling. All are described as allowing a remote attacker to execute, or potentially execute, arbitrary code outside the sandbox via a crafted HTML page. One of the Payments issues (CVE-2026-87581) additionally notes that exploitation could involve social engineering.

Sandbox escape potential

Each of the eight CVEs is described as potentially allowing code execution outside Chrome's sandbox, which is the primary isolation mechanism protecting the host system from malicious web content. Chromium's own internal severity ratings for the individual bugs range from Low to Critical, though all were assigned the same CVSS base score of 9.6 in this fact package.

Platform scope

Some advisories specify a platform: CVE-2026-87512 and CVE-2026-87528 affect Chrome on Windows, CVE-2026-87637 and CVE-2026-87558 affect Chrome on Mac, and CVE-2026-87643 affects Chrome on Android. The remaining advisories (CVE-2026-87527, CVE-2026-87448, CVE-2026-87581) do not specify a platform restriction in the source descriptions, which may indicate they affect Chrome across all desktop platforms, but this is not explicitly confirmed in the available facts.

Versions prior to the fix

All eight vulnerabilities affect versions of Google Chrome prior to 153.0.8010.36. No earlier affected version boundary is specified in the fact package.

Fixed in version 153.0.8010.36

Google has released Chrome 153.0.8010.36 for desktop, which resolves all eight vulnerabilities listed in this briefing. Chrome's built-in auto-update mechanism will typically apply this update automatically; users can also trigger an update manually via the browser's settings menu.

Update Chrome without delay

Site owners and users should confirm that Chrome is running version 153.0.8010.36 or later. Given the number of sandbox-escape-capable flaws patched in this release and their uniformly high CVSS score, applying the update promptly is advised. A browser restart is typically required to complete the update.

PatchBriefing score

6.4 / 10 · Medium

Official CVSS: 9.6

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Why this score

Each of the eight vulnerabilities carries a CVSS base score of 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), reflecting network-exploitable, low-complexity attacks requiring no privileges but some user interaction, with scope change and high impact to confidentiality, integrity, and availability. The computed PatchBriefing score of 6.4 for each entry factors in this high CVSS base, the unauthenticated-remote attack vector, and Chrome's very large install base, while none of the entries show evidence of known exploitation, public exploit code, or EPSS data in the fact package.

Affected versions

≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched
≥ 153.0.8010.36
patched

Reported fixes

Google has released Chrome 153.0.8010.36 for desktop, which resolves all eight vulnerabilities listed in this briefing. Chrome's built-in auto-update mechanism will typically apply this update automatically; users can also trigger an update manually via the browser's settings menu.

How this was built

9 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome Stable Update Fixes Eight High-Severity Memory Safety Vulnerabilities
1 article · 9 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email