CVE-2026-87464: Use After Free in WebGL in Google Chrome prior to 153.0.8010.36 allows Remote Code Execution outside Sandbox
A NVD · · CVE-2026-87464
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key metrics
- EPSS
- 0%
Key insight
The vulnerability enables arbitrary code execution outside the browser sandbox via a crafted HTML page, suggesting potential active exploitation.
Description
CVE-2026-87464 is a use-after-free vulnerability in Google Chrome's WebGL implementation that allows a remote attacker to execute arbitrary code via a crafted HTML page. The distinguishing factor is sandbox escape: the code executes outside the normal browser sandbox, enabling complete system compromise. Chromium has rated this vulnerability as "Critical". Chrome versions prior to 153.0.8010.36 are affected. Since WebGL is widely used in modern web applications, legitimate websites can be abused as attack vectors.
Risk score
- cvss base
- 45.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 0.00
- raw before weight
- 45.00
- industry weight
- 1.21
- freshness factor
- 1.00
- exploitability factor
- 1.00
- days old
- 0.00
- vendor mismatch penalty
- 0.00
Path: operational