CVE-2026-87646
A critical flaw in Google Chrome’s Web Authentication lets attackers run code outside the browser sandbox by loading a specially crafted HTML page. The bug is a use‑after‑free error that can be triggered without any user interaction. Updating to Chrome 153.0.8010.36 or later fixes the issue.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Google Chrome browsers older than version 153.0.8010.36, used by general web users.
Real-world impact
An attacker could execute arbitrary code on the victim’s computer, potentially taking full control, stealing data, or installing malware.
Why this severity
The CVSS score of 9.6 reflects that the flaw is network‑exploitable, requires no privileges, and can lead to complete compromise of confidentiality, integrity, and availability.
What to do about it
- 01Update Google Chrome to version 153.0.8010.36 or newer.
- 02Restart the browser to apply the update.
NVD description
Timeline
- Sep 9, 2026 · 5d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 9, 2026 · 4d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- chromereleases.googleblog.com/2026/09/stable-channel-upda…release notesvendor advisory
- issues.chromium.org/issues/539754136permissions required