Description
Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an out‑of‑bounds read in the Media component of Google Chrome before version 153.0.8010.36. The flaw can be triggered by a specially crafted HTML page that causes the browser to read memory outside the bounds of a buffer, leading to arbitrary code execution inside the sandbox. This allows a remote attacker to run code with the privileges of the browser process, potentially breaking the sandbox and compromising the system.

Affected Systems

All desktop users of Google Chrome on Windows, macOS, and Linux who have not upgraded past version 153.0.8010.36 are affected. The issue is present in the stable channel and applies to all revisions of the browser that include the vulnerable Media code.

Risk and Exploitability

The EPSS score is < 1%, indicating a very low probability of exploitation, while the CVSS score of 8.8 signifies a high severity vulnerability. Because the vulnerability can be exploited via a crafted HTML page, the likely attack vector is a web‑based attack, such as a malicious site or a phishing email containing a malicious link. Chromium labels the severity as High, and although the vulnerability is not listed in the CISA KEV catalog, the ability to execute arbitrary code remotely makes it a significant risk for any user who visits untrusted web content.

Generated by OpenCVE AI on September 9, 2026 at 16:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Google Chrome 153.0.8010.36 or later, which contains the patch for this media out‑of‑bounds read.
  • Configure Chrome to use the sandboxed browsing mode or apply the built‑in security features that limit file system and network access for extensions and web content.
  • Monitor network traffic for attempts to host or load malicious HTML content and block or report suspicious domains to maintain a cleaner threat environment.

Generated by OpenCVE AI on September 9, 2026 at 16:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Out‑of‑Bounds Read in Chrome Media
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Out‑of‑Bounds Read in Chrome Media

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:55:31.604Z

Reserved: 2026-09-08T22:22:43.864Z

Link: CVE-2026-87440

cve-icon Vulnrichment

Updated: 2026-09-09T12:56:08.863Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:00.240

Modified: 2026-09-10T04:18:19.047

Link: CVE-2026-87440

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T09:15:16Z

Weaknesses