Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-87643
Google Chrome vulnerability analysis and mitigation

Overview

CVE-2026-87643 is an integer overflow vulnerability in the GPU component of Google Chrome on Android that allows a remote attacker to potentially execute arbitrary code outside the browser sandbox via a crafted HTML page. It affects all versions of Google Chrome for Android prior to 153.0.8010.36. The vulnerability was reported to Google on 2026-05-15 and publicly disclosed on 2026-09-09 as part of the Chrome 153 stable channel release. It carries a CVSS v3.1 base score of 9.6 (Critical) (Chrome Releases, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-190 (Integer Overflow or Wraparound) and is associated with CAPEC-92 (Forced Integer Overflow). The flaw resides in Chrome's GPU processing component on Android, where insufficient bounds checking on integer arithmetic can result in a value wrapping around to an unexpected range. This corrupted value can then be used in memory operations, potentially enabling an attacker to write data outside intended boundaries and escape the Chrome sandbox. Exploitation requires a user to visit or be redirected to a specially crafted HTML page, making it a drive-by attack vector (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code outside the Chrome sandbox on affected Android devices, resulting in full compromise of confidentiality, integrity, and availability of the affected system. The changed scope (S:C) in the CVSS vector reflects the sandbox escape potential, meaning the impact extends beyond the browser process itself to the underlying Android operating system and user data. This could enable an attacker to access sensitive information, install malware, or perform further lateral movement on the device (GitHub Advisory, Chrome Releases).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation for CVE-2026-87643. The EPSS score is approximately 0.33%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Notably, a separate vulnerability in the same Chrome 153 release (CVE-2026-87491) does have a known in-the-wild exploit, but CVE-2026-87643 does not share this status (Chrome Releases, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify Android users running Google Chrome versions prior to 153.0.8010.36, which can be inferred from browser user-agent strings or targeted phishing campaigns.
  2. Craft malicious HTML page: Develop a specially crafted HTML page containing JavaScript or WebGL/GPU-triggering content designed to induce an integer overflow in Chrome's GPU processing component on Android.
  3. Deliver payload: Host the malicious page on an attacker-controlled server and lure the target into visiting it via phishing, malvertising, or a compromised website — no authentication or special permissions are required from the victim beyond clicking a link.
  4. Trigger integer overflow: When the victim's Chrome browser on Android renders the page, the GPU component processes attacker-controlled values that cause an integer overflow, corrupting memory in a controlled manner.
  5. Achieve sandbox escape and code execution: Leverage the memory corruption to escape the Chrome sandbox and execute arbitrary code in the context of the Android OS, potentially gaining persistent access or installing malicious payloads (Chrome Releases, GitHub Advisory).

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 153.0.8010.36 for Android (and 153.0.8010.36/.37 for Windows/Mac/Linux). Users should update Google Chrome on Android to version 153.0.8010.36 or later immediately via the Google Play Store. As a precautionary measure, users should avoid opening untrusted HTML pages or links from unknown sources until the update is applied. No configuration-based workaround is available; patching is the only definitive remediation (Chrome Releases).

Community reactions

The Chrome 153 release, which patches CVE-2026-87643 among 230 total security fixes, received coverage from security news outlets such as CyberPress, which highlighted the large number of fixes in this release. Social media activity on platforms like Bluesky noted the update, and security aggregators including VulDB and CVEFeed indexed the vulnerability shortly after disclosure. No notable individual researcher commentary specific to CVE-2026-87643 has been identified beyond standard vulnerability tracking (Chrome Releases).

Additional resources

  • Chrome Releases — Official Google Chrome 153 stable channel security advisory
  • GitHub Advisory — GHSA-8xvf-47f3-jhc3 advisory for CVE-2026-87643
  • Chromium Bug — Chromium issue tracker entry for CVE-2026-87643

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

chromium: 153.0.8010.47-1

Fixed

sid

chromium: 153.0.8010.47-1

Fixed

trixie

chromium: 153.0.8010.47-2~deb13u1

Fixed

SourceThis report was generated using AI

Related Google Chrome vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93385MEDIUM6.5
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesSep 17, 2026
CVE-2026-93386MEDIUM5.4
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesSep 17, 2026
CVE-2026-93387MEDIUM4.3
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 17, 2026
CVE-2026-93383MEDIUM4.3
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 17, 2026
CVE-2026-93384LOW3.7
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management