CVE-2026-87628: Use After Free in Cast in Google Chrome Prior to 153.0.8010.36
A NVD · · CVE-2026-87628
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key metrics
- EPSS
- 0%
Key insight
The vulnerability enables arbitrary code execution outside the sandbox by an adjacent attacker using crafted network traffic , a significant risk for Chrome-based systems.
Description
CVE-2026-87628 is a critical use-after-free vulnerability in the Cast feature of Google Chrome prior to version 153.0.8010.36. An adjacent attacker can exploit crafted network traffic to corrupt memory and potentially execute arbitrary code outside the browser sandbox. The Chromium security severity rating is critical. While not documented as actively exploited in public vulnerability databases, the severity and out-of-sandbox vector warrant attention.
Risk score
- cvss base
- 45.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 0.00
- raw before weight
- 45.00
- industry weight
- 1.21
- freshness factor
- 1.00
- exploitability factor
- 1.00
- days old
- 0.00
- vendor mismatch penalty
- 0.00
Path: operational