Description
Uninitialized resource in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 3.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via out‑of‑sandbox memory read
Action: Immediate Patch
AI Analysis

Impact

An uninitialized resource in Chrome's Media code allows a remote attacker who has already compromised the renderer process to read memory outside the sandbox through a crafted HTML page. The flaw can expose arbitrary memory contents, potentially leaking sensitive data such as credentials, cryptographic material, or other private application data, thereby undermining confidentiality. The impact is limited to the renderer process but can be leveraged to compromise the broader system if other components interact with the leaked data. The vulnerability is classified with medium severity by Chromium, indicating a noticeable but not critical risk if mitigated promptly.

Affected Systems

The issue affects Google Chrome on desktop platforms running any version earlier than 153.0.8010.36. Versions 153.0.8010.36 and newer contain the fix that was deployed in the stable channel update announced in September 2026.

Risk and Exploitability

The exploit requires a remote attacker to supply a specifically crafted HTML page that is processed by a renderer process that has been compromised. The EPSS score of <1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The low security severity indicated by a CVSS score of 3.4 and the fact that the attacker must already have bypassed the renderer sandbox lower its overall risk profile, but the memory read could still be used for sensitive information theft or as a stepping stone to further attacks. The attack vector is remote via web content, and exploitation requires the attacker’s code to run with renderer privileges.

Generated by OpenCVE AI on September 9, 2026 at 21:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 153.0.8010.36 or later to receive the official fix
  • If an update cannot be applied immediately, limit the rendering of untrusted HTML by enforcing stricter content‑security policies and tightening renderer sandboxing settings
  • Monitor the browser for abnormal renderer crashes or unusual memory access patterns to detect potential exploitation attempts

Generated by OpenCVE AI on September 9, 2026 at 21:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Media Resource Enables Out‑of‑Sandbox Memory Read in Chrome

Wed, 09 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Wed, 09 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Uninitialized Media Resource Enables Out‑of‑Sandbox Memory Read in Chrome

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Uninitialized resource in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-908
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T20:04:23.109Z

Reserved: 2026-09-08T22:23:21.383Z

Link: CVE-2026-87456

cve-icon Vulnrichment

Updated: 2026-09-09T19:50:24.807Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:01.993

Modified: 2026-09-09T20:30:57.267

Link: CVE-2026-87456

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T16:00:13Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource