CVE-2026-87657

NONE
Source

CVE-2026-87657: Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory inside ...

Microsoft Security Response CenterPublished Sep 9, 2026Modified 6d agoNVDMaturity: disclosed

Description

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

CVSS Scores

EPSS Score

EPSS Probability0.17%

Higher than 7% of all CVEs

Threat actors associated with CVE-2026-87657

Kaitan ID has linked 1 threat actor to this vulnerability based on exploit usage, campaign attribution, and intelligence reporting.

  • Earth Lusca (China) — also known as CHROMIUM, ControlX, TAG-22, FISHMONGERexploits (confidence: medium)

Exploit maturity

DisclosedThis vulnerability has been publicly disclosed but no exploit code has been observed yet.

  • No vendor patch available yet.

Exploitation probability (EPSS)

EPSS exploitation probability: 0.2% (remained stable from 0.2%, 0% change). This vulnerability ranks in the top 93% of all CVEs by exploitation likelihood. Last updated on Sep 15, 2026.

Primary source

Original advisory or reference for this vulnerability (via NVD).

https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html