CVE-2026-87585
Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code
CVSS
—
No CVSS
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 9, 2026 · Last modified: Sep 9, 2026 · CWE-415
Not enough EPSS history yet.
Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-799077.8 HIG—
———Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.3hCVE-2026-819507.8 HIG—
———Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.4hCVE-2026-800808.8 HIG—
———Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.4hCVE-2026-775048.8 HIG—
———Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.4hCVE-2026-774939.8 CRI—
———Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.4hCVE-2026-729588.2 HIG—
———Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.3h