Medium · 6.4 Browsers CVE-2026-87634 CVE-2026-87488 CVE-2026-87646 CVE-2026-87438
Google Chrome Stable Update Fixes Eight High-Severity Use-After-Free and Memory Corruption Flaws
Google has released Chrome 153.0.8010.36 for desktop, patching eight vulnerabilities including multiple use-after-free and out-of-bounds write issues across WebGL, ANGLE, Dawn, WebPackaging, Web Authentication, Tint, and Core components, several rated Critical or High by Chromium's own severity scale.
- Chrome Releases (Stable) vendor · view ↗
- NVD (NIST) database 1mo ago · view ↗
- NVD (NIST) database 1mo ago · view ↗
- NVD (NIST) database 1mo ago · view ↗
- NVD (NIST) database 1mo ago · view ↗
- NVD (NIST) database 1mo ago · view ↗
- NVD (NIST) database 1mo ago · view ↗
- NVD (NIST) database 1mo ago · view ↗
- NVD (NIST) database 1mo ago · view ↗
AI summary
Google has published a Stable Channel update for Chrome on desktop, addressing eight distinct vulnerabilities identified by Chrome's security team and external reporters. All eight issues share a CVSS base score of 9.6 and involve memory-safety defects — primarily use-after-free and out-of-bounds write conditions — in various Chrome components including WebGL, ANGLE, Dawn, WebPackaging, Web Authentication, Tint, and Core. Chromium's own internal severity ratings for these issues range from Medium to Critical. The vendor advisory does not state that any of these vulnerabilities have been exploited in the wild.
Eight vulnerabilities patched in a single Chrome update
Google released a Stable Channel update for Chrome on desktop that fixes eight separate CVEs: CVE-2026-87634 (WebPackaging), CVE-2026-87488 (WebGL, Android), CVE-2026-87646 (Web Authentication), CVE-2026-87438 (WebGL, Android), CVE-2026-87621 (ANGLE, Windows), CVE-2026-87520 (Dawn, Android), CVE-2026-87470 (Tint, Mac), and CVE-2026-87504 (Core). Each is described by the vendor as potentially allowing a remote attacker to execute arbitrary code outside the Chrome sandbox via a crafted HTML page, with the exception of CVE-2026-87504, which requires a crafted Chrome extension and social engineering.
Memory-safety defects: use-after-free and out-of-bounds write
Six of the eight issues are use-after-free vulnerabilities (CWE-416): CVE-2026-87634 in WebPackaging, CVE-2026-87488 in WebGL, CVE-2026-87646 in Web Authentication, CVE-2026-87520 in Dawn, and CVE-2026-87504 in Core. Two are out-of-bounds write vulnerabilities (CWE-787): CVE-2026-87438 in WebGL and CVE-2026-87621 in ANGLE. CVE-2026-87470 is described as an improper quantity validation issue (CWE-1284) in the Tint component. Use-after-free bugs occur when a program continues to use memory after it has been freed, which an attacker can exploit to corrupt program state; out-of-bounds write bugs allow writing data beyond allocated memory boundaries, which can similarly be leveraged to corrupt memory and potentially achieve code execution.
Potential for sandbox escape and arbitrary code execution
Each vulnerability is rated with a CVSS base score of 9.6 (CVSS:3.1 AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), reflecting network-exploitable issues requiring low attack complexity and no privileges, though user interaction is needed. The vendor's own Chromium severity ratings vary: CVE-2026-87488 and CVE-2026-87438 are rated Critical, CVE-2026-87646, CVE-2026-87621, and CVE-2026-87520 are rated High, CVE-2026-87470 and CVE-2026-87504 are rated Medium, and CVE-2026-87634 is rated Low. For most of these flaws, successful exploitation via a crafted HTML page could allow a remote attacker to execute arbitrary code outside Chrome's sandbox protections, which would represent a significant compromise of the affected system. CVE-2026-87504 differs in that it requires a malicious Chrome extension combined with social engineering rather than simply visiting a web page.
Who is affected
Users of Google Chrome on desktop are affected by this update. Several of the individual vulnerabilities are specific to a platform: CVE-2026-87488 and CVE-2026-87438 affect Chrome on Android, CVE-2026-87621 affects Chrome on Windows, and CVE-2026-87470 affects Chrome on Mac. The remaining vulnerabilities (CVE-2026-87634, CVE-2026-87646, CVE-2026-87520, and CVE-2026-87504) are not described as platform-specific in the vendor advisory. Products built on the same Chromium engine may also be affected, though the fact package provided does not confirm this.
Affected and fixed versions
All eight vulnerabilities affect Google Chrome versions prior to 153.0.8010.36. The vendor advisory does not specify a starting version for the affected range, so the full extent of older vulnerable releases is not stated in the available facts.
Fix available
Google has released Chrome 153.0.8010.36 for desktop, which resolves all eight vulnerabilities described in this briefing. Chrome's update mechanism typically rolls out automatically, but users and administrators should verify their installed version.
Recommended action
Verify that Chrome is updated to version 153.0.8010.36 or later by checking the browser's About page, and restart the browser if an update is pending, since updates do not take effect until Chrome is relaunched. Organizations managing Chrome deployments at scale should confirm that the update has been pushed across all managed devices.
PatchBriefing score
6.4 / 10 · Medium
Official CVSS: 9.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Why this score
Each of the eight vulnerabilities carries a CVSS base score of 9.6 under the vector AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, indicating network-based attacks with low complexity, no required privileges, and a scope change into the operating system outside Chrome's sandbox, though some user interaction (such as visiting a crafted page) is required. The computed PatchBriefing score of 6.4 reflects this high CVSS base score plus modest additions for the unauthenticated-remote attack vector and Chrome's very large install base, but is tempered by the absence of confirmed exploitation in the wild, no public exploit code, and the fact that a fix is already available. Chromium's own internal severity ratings for individual bugs range from Low to Critical, reflecting differences in exploitability and impact that are not fully captured by the shared CVSS score.
Affected versions
- ≥ 153.0.8010.36
- patched
- ≥ 153.0.8010.36
- patched
- ≥ 153.0.8010.36
- patched
- ≥ 153.0.8010.36
- patched
- ≥ 153.0.8010.36
- patched
- ≥ 153.0.8010.36
- patched
- ≥ 153.0.8010.36
- patched
- ≥ 153.0.8010.36
- patched
Reported fixes
Google has released Chrome 153.0.8010.36 for desktop, which resolves all eight vulnerabilities described in this briefing. Chrome's update mechanism typically rolls out automatically, but users and administrators should verify their installed version.
How this was built
9 source records were collected, matched and used to prepare the report above.
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email