Description
Information leak in Enterprise in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The flaw allows a remote attacker to read unprotected data during browsing of a specially crafted HTML page. The vulnerability is categorized as a medium‑severity information disclosure issue that can expose sensitive information to the attacker. No additional user privileges or system components are required beyond the normal rendering of the page.

Affected Systems

Google Chrome on Windows versions prior to 153.0.8010.36 are affected. The issue applies to the Enterprise distribution of the browser and affects all users on systems running these releases.

Risk and Exploitability

The vulnerability can be exploited remotely by serving the crafted page to a user, typically through a malicious website or an in‑mail link. Because the flaw is limited to the rendering engine of the browser, it does not provide remote code execution or privilege escalation, but the information gained could be leveraged in later attacks. The CVSS score is 6.5, which is Medium, and the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog, so public exploitation is not confirmed yet, yet the risk is non‑negligible if the software remains unpatched.

Generated by OpenCVE AI on September 9, 2026 at 16:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later on all Windows machines
  • Configure group policy or Chromium flags to block loading of local or untrusted HTML resources if an immediate upgrade is not possible
  • Regularly monitor for unexpected data exfiltration from the browser environment

Generated by OpenCVE AI on September 9, 2026 at 16:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Crafted HTML Page in Google Chrome Enterprise on Windows
First Time appeared Google
Google chrome
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome
Microsoft
Microsoft windows

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Information leak in Enterprise in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T14:37:21.108Z

Reserved: 2026-09-08T22:23:16.146Z

Link: CVE-2026-87454

cve-icon Vulnrichment

Updated: 2026-09-09T14:35:46.423Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:01.777

Modified: 2026-09-09T17:02:54.670

Link: CVE-2026-87454

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T03:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor