• PATCH AVAILABLE

CVE-2026-87613: pre-auth remote code execution in Google Chrome

A remote attacker can execute arbitrary code in Google Chrome by exploiting an incorrect reference resolution in Extensions; tracked as CVE-2026-87613. The flaw affects Chrome 153.x releases before 153.0.8010.36 and can be triggered by crafted network traffic, requiring no user interaction or privileges but network access and a successful complex request to the browser.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9CRITICAL
EPSS
0.0047
CWE
CWE-706
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgently update Chrome to 153.0.8010.36 or later — this issue carries a critical CVSS 9.0 rating and has been fixed in that release. If immediate update is not possible, restrict network exposure to untrusted sources and monitor for anomalous browser activity.

What is CVE-2026-87613?

A remote attacker can execute arbitrary code in Google Chrome by exploiting an incorrect reference resolution in Extensions; tracked as CVE-2026-87613. The flaw affects Chrome 153.x releases before 153.0.8010.36 and can be triggered by crafted network traffic, requiring no user interaction or privileges but network access and a successful complex request to the browser.

Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of Google Chrome are affected?

BRANCHAFFECTEDFIXED
153.x153.0.8010.36 – before 153.0.8010.36153.0.8010.36

Is CVE-2026-87613 being exploited?

There are no public reports of exploitation or public exploit code as of 2026-09-30.

How to fix CVE-2026-87613

  1. Update Google Chrome to version 153.0.8010.36 or later.
  2. If you cannot update immediately, restrict browser access to untrusted networks and block suspicious inbound traffic.
  3. Monitor endpoint and network logs for unusual Chrome processes, unexpected child processes, or anomalous network connections.
  4. Follow Google's official guidance and deploy the vendor patch as soon as it is available to your fleet.

Frequently asked questions

Is CVE-2026-87613 being actively exploited?

There are no public reports of active exploitation and no public exploit code as of 2026-09-30; CISA has not listed it in the Known Exploited Vulnerabilities catalog.

Which Chrome versions are affected by CVE-2026-87613?

Chrome 153.x releases before 153.0.8010.36 are affected; the issue is fixed in 153.0.8010.36.

Is there a patch for CVE-2026-87613?

Yes, Google fixed the vulnerability in Chrome version 153.0.8010.36; update to that version or later.

Does CVE-2026-87613 require authentication?

No, the vulnerability can be triggered without authentication or user interaction, but it requires the attacker to send crafted network traffic to the browser.

References