• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-87492: pre-auth remote code execution in Google Chrome

A remote attacker can run code outside the Chrome sandbox by getting a user to load a crafted page in affected Chrome builds; this is tracked as CVE-2026-87492. The flaw exists in DevTools authorization and affects Chrome versions before 153.0.8010.36 (fixed in 153.0.8010.36). Exploitation requires a user to visit a malicious page (user interaction is required).

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.6CRITICAL
EPSS
0.00444
CWE
CWE-863
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code is available, so update Chrome to 153.0.8010.36 immediately or block untrusted web content until patched.

What is CVE-2026-87492?

A remote attacker can run code outside the Chrome sandbox by getting a user to load a crafted page in affected Chrome builds; this is tracked as CVE-2026-87492. The flaw exists in DevTools authorization and affects Chrome versions before 153.0.8010.36 (fixed in 153.0.8010.36). Exploitation requires a user to visit a malicious page (user interaction is required).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Which versions of Google Chrome are affected?

BRANCHAFFECTEDFIXED
153.x153.0.8010.36 – before 153.0.8010.36153.0.8010.36

Is CVE-2026-87492 being exploited?

Public exploit code is available.

How to fix CVE-2026-87492

  1. Update Chrome to 153.0.8010.36 (the fixed release).
  2. Block or restrict access to untrusted web content and use network filtering for risky sites.
  3. Monitor endpoints for unexpected sandbox escape indicators and review browser telemetry for suspicious renderer activity.
  4. Apply vendor guidance for browser hardening and ensure automatic updates are enabled.

Frequently asked questions

Is CVE-2026-87492 being actively exploited?

Public exploit code for CVE-2026-87492 is available.

Which Chrome versions are affected by CVE-2026-87492?

Chrome versions before 153.0.8010.36 are affected; the issue is fixed in 153.0.8010.36.

Is there a patch for CVE-2026-87492?

Yes. Google fixed the issue in Chrome version 153.0.8010.36.

Does CVE-2026-87492 require authentication?

No authentication is required, but exploitation requires a user to load a crafted page (user interaction).

References