---
id: CVE-2026-87628
title: >-
  Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an
  adjacent attacker to potentially execute arbitrary code outside the sandbox
  via crafted network traffic
summary: >-
  Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an
  adjacent attacker to potentially execute arbitrary code outside the sandbox
  via crafted network traffic. (Chromium security severity: Critical)
severity: high
cvss: 8.3
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: google
product: chrome
affected:
  - chrome < 153.0.8010.36
patched:
  - chrome 153.0.8010.36
published: '2026-09-09'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T04:18:29.850'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87628'
references:
  - url: >-
      https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
    label: chrome-cve-admin@google.com
  - url: 'https://issues.chromium.org/issues/553770012'
    label: chrome-cve-admin@google.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-09T14:25:56.570271Z'
epss: 0.00191
epssPercentile: 0.07715
ingestedAt: '2026-09-09T01:17:17.513Z'
---

## Overview

Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)

## Affected

- `chrome < 153.0.8010.36`

## Remediation

Upgrade past the affected range:

- `chrome 153.0.8010.36`
