
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-87654 is a heap-based buffer overflow vulnerability in ANGLE (Almost Native Graphics Layer Engine) in Google Chrome on Windows that allows a remote attacker to execute arbitrary code outside the browser sandbox via a crafted HTML page. It affects all Google Chrome versions prior to 153.0.8010.36 on Windows. The vulnerability was reported by Google on July 19, 2026, and publicly disclosed on September 8–9, 2026, alongside the Chrome 153 stable channel release. It carries a CVSS v3.1 base score of 9.6 (Critical) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) within Chrome's ANGLE graphics abstraction layer, which translates OpenGL ES API calls to platform-specific graphics APIs (e.g., Direct3D on Windows). Insufficient bounds checking in ANGLE's buffer handling allows a specially crafted HTML page to trigger a heap overflow, enabling an attacker to corrupt memory and achieve code execution outside the Chrome sandbox. Exploitation requires user interaction — specifically, a victim visiting a malicious web page — but no authentication or special privileges are required on the attacker's side. The Chromium issue tracker references bug ID 536444790 for this vulnerability (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote, unauthenticated attacker to execute arbitrary code outside the Chrome sandbox on Windows systems, effectively bypassing Chrome's primary security boundary. This grants the attacker code execution at the privilege level of the Chrome process user, enabling data theft, malware installation, lateral movement within a network, or full system compromise. The scope is marked as "Changed" in the CVSS vector, reflecting the sandbox escape component that extends impact beyond the browser process itself (GitHub Advisory, Chrome Releases).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation for CVE-2026-87654 specifically. The EPSS score is approximately 0.334%, indicating a relatively low near-term exploitation probability. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable due to the required user interaction. Notably, the same Chrome 153 release advisory confirms that an exploit for a separate vulnerability (CVE-2026-87491) exists in the wild, but CVE-2026-87654 is not listed as actively exploited. It is not currently listed in the CISA Known Exploited Vulnerabilities catalog (Chrome Releases, GitHub Advisory).
chrome.exe) to unknown external IP addresses or domains following a web page visit; unusual DNS queries originating from the Chrome process.chrome.exe on Windows (e.g., cmd.exe, powershell.exe, wscript.exe) that are not typical browser subprocesses; GPU process (chrome.exe --type=gpu-process) exhibiting anomalous behavior or crashing repeatedly.chrome.exe or its GPU subprocess around the time of a suspicious web visit; crash dumps referencing ANGLE or GPU-related modules.%APPDATA%, %TEMP%) by the Chrome process; new scheduled tasks or registry run keys created after a browser session.Google has released Chrome 153.0.8010.36 (Linux) and 153.0.8010.36/.37 (Windows/Mac) which patches CVE-2026-87654. Users should update Google Chrome immediately via the browser's built-in update mechanism (Settings → Help → About Google Chrome). Microsoft has also acknowledged the vulnerability for Chromium-based Edge and published guidance via the MSRC. As interim measures, organizations should enforce Chrome auto-updates via enterprise policy, restrict user privileges to limit post-exploitation impact, and consider deploying endpoint detection and response (EDR) solutions to detect anomalous process behavior from the browser (Chrome Releases, Microsoft MSRC).
The Chrome 153 release, which included 230 security fixes, received broad coverage from security-focused outlets including GBHackers and CyberPress, which highlighted the large number of fixes and the presence of an actively exploited vulnerability (CVE-2026-87491) in the same release. Social media posts on Bluesky and Reddit's r/pwnhub discussed the release in the context of daily CVE briefings. Italian tech outlet Telefonino.net urged users to update Chrome urgently. No specific high-profile researcher commentary focused exclusively on CVE-2026-87654 has been identified (GBHackers, CyberPress).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."