Description
Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Code Execution outside the sandbox on Windows
Action: Update Chrome
AI Analysis

Impact

A race condition in the Chrome Updater on Windows allows a local attacker to execute arbitrary code outside the sandbox by manipulating a local program. The flaw is a typical concurrency problem that can be exploited to bypass sandbox protections, potentially giving an attacker full control over the affected system.

Affected Systems

Google Chrome versions prior to 153.0.8010.36 on Windows are affected. This includes desktop installations where the updater runs with elevated privileges. No other vendors or products are currently cited.

Risk and Exploitability

The vulnerability can be leveraged by a local user or a program with local execution privileges. The CVSS score of 8.1 indicates a high severity, and the EPSS score is under 1%, suggesting low likelihood of exploitation in the wild, but the issue is not listed in CISA KEV. The Chromium severity is Medium, indicating a moderate risk if exploited. The attack vector is local, requiring the attacker to have access to a local program or the ability to execute code on the machine.

Generated by OpenCVE AI on September 9, 2026 at 17:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Chrome 153.0.8010.36 or later to contain the race condition and restrict updater execution.
  • Remove or disable the Chrome updater executable from the system to eliminate the concurrency vulnerability.
  • Apply Windows local policy hardening such as AppLocker or UAC restrictions to limit the execution of untrusted local programs.

Generated by OpenCVE AI on September 9, 2026 at 17:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Race Condition in Chrome Updater Enabling Local Code Execution Outside Sandbox on Windows

Wed, 09 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome
Microsoft
Microsoft windows

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Title Race Condition in Chrome Updater Enabling Local Code Execution Outside Sandbox on Windows

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
Weaknesses CWE-367
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:56:26.382Z

Reserved: 2026-09-08T22:37:28.923Z

Link: CVE-2026-87457

cve-icon Vulnrichment

Updated: 2026-09-09T14:20:00.452Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:02.107

Modified: 2026-09-10T04:18:19.730

Link: CVE-2026-87457

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T10:30:04Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition