CVE-2026-87578
Medium
Elevated severity or exploit probability.
CVSS base
8.3
HIGH
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
0.1%
3.1th percentile
CISA KEV
Not listed
Weakness / dates
CWE-416
Published 2026-09-09 · modified 2026-09-10
CVSS breakdown
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
| Attack Vector | A | Adjacent |
| Attack Complexity | H | High |
| Privileges Required | N | None |
| User Interaction | N | None |
| Scope | C | Changed |
| Confidentiality | H | High |
| Integrity | H | High |
| Availability | H | High |
Timeline
- 2026-09-09 — Published (NVD)
- 2026-09-10 — Last modified (NVD)
Description
Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)