CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-87464: RCE outside sandbox in Chromium prior to 153.0.8010.36

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7017

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-87464: RCE outside sandbox in Chromium prior to 153.0.8010.36

A use-after-free vulnerability in WebGL (CVE-2026-87464) affects Google Chrome and Chromium-based browsers prior to version 153.0.8010.36. An attacker can exploit the flaw through a crafted HTML page to achieve remote code execution outside the sandbox with critical severity.

Why it matters: Organizations running Chrome or Chromium-based browsers need to update to version 153.0.8010.36 or later immediately, as this critical vulnerability allows arbitrary code execution outside the browser sandbox.

VendorsGoogleLinux
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-87464: RCE outside sandbox in Chromium prior to 153.0.8010.36

A use-after-free vulnerability in WebGL allowed remote code execution outside the sandbox in Chromium and Chrome prior to version 153.0.8010.36. An attacker could exploit this through a crafted HTML page with critical severity. The Chromium security tracker restricts further technical details.

Why it matters: Chrome and Chromium users face immediate remote code execution risk; patch to 153.0.8010.36 or later, and note that all Chromium-derived browsers including Edge, Brave, and Vivaldi require updates.

VendorsGoogleLinux
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary