DIRAS TAKE
Urgent: public exploit code is available, so update Chrome to 153.0.8010.36 immediately or block untrusted web content until patched.
What is CVE-2026-87492?
A remote attacker can run code outside the Chrome sandbox by getting a user to load a crafted page in affected Chrome builds; this is tracked as CVE-2026-87492. The flaw exists in DevTools authorization and affects Chrome versions before 153.0.8010.36 (fixed in 153.0.8010.36). Exploitation requires a user to visit a malicious page (user interaction is required).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Which versions of Google Chrome are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 153.x | 153.0.8010.36 – before 153.0.8010.36 | 153.0.8010.36 |
Is CVE-2026-87492 being exploited?
Public exploit code is available.
How to fix CVE-2026-87492
- Update Chrome to 153.0.8010.36 (the fixed release).
- Block or restrict access to untrusted web content and use network filtering for risky sites.
- Monitor endpoints for unexpected sandbox escape indicators and review browser telemetry for suspicious renderer activity.
- Apply vendor guidance for browser hardening and ensure automatic updates are enabled.
Frequently asked questions
Is CVE-2026-87492 being actively exploited?
Public exploit code for CVE-2026-87492 is available.
Which Chrome versions are affected by CVE-2026-87492?
Chrome versions before 153.0.8010.36 are affected; the issue is fixed in 153.0.8010.36.
Is there a patch for CVE-2026-87492?
Yes. Google fixed the issue in Chrome version 153.0.8010.36.
Does CVE-2026-87492 require authentication?
No authentication is required, but exploitation requires a user to load a crafted page (user interaction).
References
- nvd.nist.gov/vuln/detail/CVE-2026-87492
- cve.org/CVERecord?id=CVE-2026-87492
- chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
- issues.chromium.org/issues/529123409
- All Google CVEs on CVE Radar
- CVEs published in September 2026