DIRAS TAKE
Urgently update Chrome to 153.0.8010.36 or later — this issue carries a critical CVSS 9.0 rating and has been fixed in that release. If immediate update is not possible, restrict network exposure to untrusted sources and monitor for anomalous browser activity.
What is CVE-2026-87613?
A remote attacker can execute arbitrary code in Google Chrome by exploiting an incorrect reference resolution in Extensions; tracked as CVE-2026-87613. The flaw affects Chrome 153.x releases before 153.0.8010.36 and can be triggered by crafted network traffic, requiring no user interaction or privileges but network access and a successful complex request to the browser.
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Which versions of Google Chrome are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 153.x | 153.0.8010.36 – before 153.0.8010.36 | 153.0.8010.36 |
Is CVE-2026-87613 being exploited?
There are no public reports of exploitation or public exploit code as of 2026-09-30.
How to fix CVE-2026-87613
- Update Google Chrome to version 153.0.8010.36 or later.
- If you cannot update immediately, restrict browser access to untrusted networks and block suspicious inbound traffic.
- Monitor endpoint and network logs for unusual Chrome processes, unexpected child processes, or anomalous network connections.
- Follow Google's official guidance and deploy the vendor patch as soon as it is available to your fleet.
Frequently asked questions
Is CVE-2026-87613 being actively exploited?
There are no public reports of active exploitation and no public exploit code as of 2026-09-30; CISA has not listed it in the Known Exploited Vulnerabilities catalog.
Which Chrome versions are affected by CVE-2026-87613?
Chrome 153.x releases before 153.0.8010.36 are affected; the issue is fixed in 153.0.8010.36.
Is there a patch for CVE-2026-87613?
Yes, Google fixed the vulnerability in Chrome version 153.0.8010.36; update to that version or later.
Does CVE-2026-87613 require authentication?
No, the vulnerability can be triggered without authentication or user interaction, but it requires the attacker to send crafted network traffic to the browser.
References
- nvd.nist.gov/vuln/detail/CVE-2026-87613
- cve.org/CVERecord?id=CVE-2026-87613
- chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
- issues.chromium.org/issues/501889544
- All Google CVEs on CVE Radar
- CVEs published in September 2026