CRITICAL 9.6 NVD
CVE-2026-87558
Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a craft
Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Affected Products
- apple/macos
- google/chrome
References
- https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027
- https://issues.chromium.org/issues/553128689
This critical severity vulnerability with a CVSS score of 9.6 was published on 2026-09-09 via NVD. Affected: apple/macos, google/chrome.
Risk Timeline
CVE Disclosed2026-09-09 · 1 day ago
Remediation Resources
Analysis & PoC
issues.chromium.org/issues/553128689Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-87470 | Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8 | CRITICAL | 9.6 |
| CVE-2026-87607 | Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allow | CRITICAL | 9.6 |
| CVE-2026-87609 | Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allo | CRITICAL | 9.6 |
| CVE-2026-87637 | Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 a | CRITICAL | 9.6 |
| CVE-2026-87535 | Information loss or omission in Safebrowsing in Google Chrome on on Mac prior to | MEDIUM | 6.5 |
| CVE-2026-87545 | Information leak in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 all | MEDIUM | 6.5 |
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.