
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-87643 is an integer overflow vulnerability in the GPU component of Google Chrome on Android that allows a remote attacker to potentially execute arbitrary code outside the browser sandbox via a crafted HTML page. It affects all versions of Google Chrome for Android prior to 153.0.8010.36. The vulnerability was reported to Google on 2026-05-15 and publicly disclosed on 2026-09-09 as part of the Chrome 153 stable channel release. It carries a CVSS v3.1 base score of 9.6 (Critical) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-190 (Integer Overflow or Wraparound) and is associated with CAPEC-92 (Forced Integer Overflow). The flaw resides in Chrome's GPU processing component on Android, where insufficient bounds checking on integer arithmetic can result in a value wrapping around to an unexpected range. This corrupted value can then be used in memory operations, potentially enabling an attacker to write data outside intended boundaries and escape the Chrome sandbox. Exploitation requires a user to visit or be redirected to a specially crafted HTML page, making it a drive-by attack vector (Chrome Releases, GitHub Advisory).
Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code outside the Chrome sandbox on affected Android devices, resulting in full compromise of confidentiality, integrity, and availability of the affected system. The changed scope (S:C) in the CVSS vector reflects the sandbox escape potential, meaning the impact extends beyond the browser process itself to the underlying Android operating system and user data. This could enable an attacker to access sensitive information, install malware, or perform further lateral movement on the device (GitHub Advisory, Chrome Releases).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation for CVE-2026-87643. The EPSS score is approximately 0.33%, indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Notably, a separate vulnerability in the same Chrome 153 release (CVE-2026-87491) does have a known in-the-wild exploit, but CVE-2026-87643 does not share this status (Chrome Releases, GitHub Advisory).
Google has addressed this vulnerability in Chrome 153.0.8010.36 for Android (and 153.0.8010.36/.37 for Windows/Mac/Linux). Users should update Google Chrome on Android to version 153.0.8010.36 or later immediately via the Google Play Store. As a precautionary measure, users should avoid opening untrusted HTML pages or links from unknown sources until the update is applied. No configuration-based workaround is available; patching is the only definitive remediation (Chrome Releases).
The Chrome 153 release, which patches CVE-2026-87643 among 230 total security fixes, received coverage from security news outlets such as CyberPress, which highlighted the large number of fixes in this release. Social media activity on platforms like Bluesky noted the update, and security aggregators including VulDB and CVEFeed indexed the vulnerability shortly after disclosure. No notable individual researcher commentary specific to CVE-2026-87643 has been identified beyond standard vulnerability tracking (Chrome Releases).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."