GoogleCVE-2026-87628
Google Chrome: use after free
High8.3CVE-2026-87628 · Published Sep 9, 2026 · updated Sep 10, 2026
Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Chrome Product | >= 153.0.8010.36, < 153.0.8010.36 | 153.0.8010.36 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-416
More Google advisories
All Google| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 9 | Google cel-go: excessive memory allocation | Medium6.9 | 0.29.0 |
| Sep 9 | Google Chrome: clickjacking | Medium5.4 | 153.0.8010.36 |
| Sep 9 | Google Chrome: remote attacker could bypass system access restrictions | Medium5.4 | 153.0.8010.36 |
| Sep 9 | Google Chrome: use after free | Low3.1 | 153.0.8010.36 |
| Sep 9 | Google Chrome: information disclosure | Medium4.3 | 153.0.8010.36 |
| Sep 9 | Google Chrome: use after free | Critical9.6 | 153.0.8010.36 |