Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-87638

CVE-2026-87638: Google Chrome RCE Vulnerability

CVE-2026-87638 is a remote code execution flaw in Google Chrome affecting versions prior to 153.0.8010.36. An out of bounds write in Media allows attackers to execute code outside the sandbox. This post covers technical details, impact, and mitigation.

Updated:

CVE-2026-87638 Overview

CVE-2026-87638 is an out-of-bounds write vulnerability in the Media component of Google Chrome. The flaw affects Chrome versions prior to 153.0.8010.36 and allows a remote attacker to potentially execute arbitrary code outside the Chrome sandbox. Exploitation requires the victim to load a crafted HTML page in the browser. The vulnerability is classified under [CWE-787] and carries a network attack vector with required user interaction. Google credits the Chromium security team with a Medium severity rating, while the National Vulnerability Database rates the issue as Critical due to the potential for sandbox escape and full compromise of the browser process.

Critical Impact

Successful exploitation can lead to arbitrary code execution outside the Chrome sandbox, enabling attackers to compromise the host system through a single malicious web page.

Affected Products

  • Google Chrome versions prior to 153.0.8010.36 (Desktop)
  • Chromium-based browsers incorporating the vulnerable Media component
  • All operating systems supported by Chrome Desktop (Windows, macOS, Linux)

Discovery Timeline

  • 2026-09-09 - CVE-2026-87638 published to the National Vulnerability Database
  • 2026-09-10 - Last updated in NVD database

Technical Details for CVE-2026-87638

Vulnerability Analysis

The vulnerability resides in the Media subsystem of Chrome, which handles decoding and playback of audio and video content. An out-of-bounds write [CWE-787] occurs when the component writes data past the boundary of an allocated buffer. Attackers can leverage this memory corruption primitive to overwrite adjacent heap structures, corrupt function pointers, or hijack control flow inside the renderer or associated media process. Because the advisory notes the issue can lead to code execution outside the sandbox, the vulnerability likely reaches a privileged process that handles media data. Successful exploitation gives attackers native code execution on the victim host with the privileges of the compromised Chrome process.

Root Cause

The underlying defect is an out-of-bounds write in Chrome's Media component. This class of bug typically stems from missing bounds checks, integer arithmetic errors during buffer size computation, or incorrect assumptions about attacker-controlled media container fields. The Chromium team has not published detailed root-cause information at this time. Additional technical context is tracked in the Chromium Issue Tracker Entry.

Attack Vector

Exploitation requires a user to visit a crafted HTML page containing malicious media content. No authentication is required, and the attack is delivered over the network. The user interaction requirement is limited to loading the attacker-controlled page, which can be achieved through phishing, malvertising, or a compromised website. Because the scope changes from the renderer sandbox to the host, attackers gain arbitrary code execution capabilities that persist beyond the browser tab.

No public proof-of-concept exploit is available in the referenced sources. Refer to the Google Chrome Desktop Update for vendor details.

Detection Methods for CVE-2026-87638

Indicators of Compromise

  • Chrome renderer or GPU process crashes containing media decoder frames in the stack trace
  • Unexpected child processes spawned by chrome.exe following media playback events
  • Outbound network connections from the browser process to previously unseen infrastructure after visiting an untrusted site
  • Presence of Chrome installations reporting versions below 153.0.8010.36

Detection Strategies

  • Inventory browser versions across the fleet and flag hosts running Chrome builds earlier than 153.0.8010.36
  • Alert on process lineage anomalies where Chrome spawns shells, script interpreters, or LOLBins
  • Correlate Chrome crash telemetry with subsequent suspicious binary execution on the same host
  • Deploy web proxy filtering to identify traffic to known malvertising and exploit-kit domains

Monitoring Recommendations

  • Ingest browser crash reports and endpoint process telemetry into a centralized data lake for correlation
  • Monitor for unsigned or newly created executables written to user-writable paths after web browsing sessions
  • Track DNS and HTTP requests from browser processes for beaconing patterns following exploitation attempts
  • Review Windows Defender ATP, macOS EndpointSecurity, or Linux eBPF telemetry for anomalous syscall patterns originating from the browser

How to Mitigate CVE-2026-87638

Immediate Actions Required

  • Update Google Chrome to version 153.0.8010.36 or later on all endpoints
  • Restart the browser after applying the update to ensure the patched binaries are loaded
  • Push the update through managed browser deployment tools such as Chrome Browser Cloud Management or enterprise MDM
  • Prioritize patching for internet-facing workstations and users who handle sensitive data

Patch Information

Google released the fix in the Chrome Stable channel update announced in the Google Chrome Desktop Update. Users should upgrade to 153.0.8010.36 or later. Chromium-based browsers such as Microsoft Edge, Brave, Opera, and Vivaldi should be updated once their vendors incorporate the upstream patch.

Workarounds

  • Restrict browsing to trusted domains via enterprise web filtering while patch deployment is in progress
  • Disable autoplay for media content and block untrusted third-party media sources
  • Enforce Chrome Site Isolation and enhanced Safe Browsing to reduce exploitation surface
  • Use application allowlisting to prevent execution of unsigned binaries dropped by browser exploits
bash
# Verify Chrome version on Windows
reg query "HKLM\SOFTWARE\Google\Chrome\BLBeacon" /v version

# Verify Chrome version on macOS
defaults read /Applications/Google\ Chrome.app/Contents/Info CFBundleShortVersionString

# Verify Chrome version on Linux
google-chrome --version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.