CVE-2026-87533 Details
Description
Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
A use-after-free vulnerability has been identified in the DevTools component of Google Chrome. This issue affects versions prior to 153.0.8010.36. The vulnerability allows a local attacker to execute arbitrary code outside of the sandbox by exploiting a flaw in how DevTools manages target sessions. The problem arises from a reentrancy issue that can lead to memory corruption, enabling the execution of unauthorized code.
Users should update to Google Chrome version 153.0.8010.36 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html | [email protected] | Release NotesVendor Advisory |
| https://issues.chromium.org/issues/521620916 | [email protected] | ExploitIssue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| google chrome | < 153.0.8010.36 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 10, 2026 | Initial Analysis | [email protected] |
| Sep 10, 2026 | CVE Modified | CISA-ADP |
| Sep 9, 2026 | CVE Modified | CISA-ADP |
| Sep 9, 2026 | New CVE Received | [email protected] |