Description
Use after free in Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

Use after free bug in Chrome's Platform component before version 153.0.8010.36 allows an attacker to run arbitrary code inside the sandbox via a crafted HTML page. The flaw is a classic use‑after‑free (CWE-416) and improper access to freed memory (CWE-825). Based on the description, it is inferred that the flaw could escape the sandbox and compromise the host. This vulnerability permits a remote attacker to tamper with local data, take over the browser process, and gain code execution on the user’s system.

Affected Systems

The issue affects Google Chrome browsers running versions earlier than 153.0.8010.36. Systems with a Chrome installation at or below that version are vulnerable. The vulnerability is confined to the Chrome application itself and does not involve the underlying operating system.

Risk and Exploitability

This vulnerability has a CVSS score of 8.8, indicating high severity, and is tied to a remote attacker delivering a malicious web page. The EPSS score is < 1%, indicating a very low but non‑zero probability of exploitation, and the flaw is not listed in CISA’S KEV catalog. Exploitation requires the victim to visit a crafted page; a successful exploit would grant code execution within the Chrome sandbox, potentially escalating to the host if the sandbox is bypassed. Based on the description, it is inferred that risk is high for users who browse untrusted content.

Generated by OpenCVE AI on September 9, 2026 at 15:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.36 or later.
  • Enable Chrome’s Safe Browsing and enforce content security policies to block malicious scripts from untrusted origins.
  • Run Chrome in a virtualized or containerized environment to isolate the browser from the host system.

Generated by OpenCVE AI on September 9, 2026 at 15:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Platform Enables Remote Code Execution chromium-browser: chromium-browser: Use after free in Platform
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Wed, 09 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Platform Enables Remote Code Execution

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Use after free in Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:55:27.324Z

Reserved: 2026-09-08T22:37:39.684Z

Link: CVE-2026-87460

cve-icon Vulnrichment

Updated: 2026-09-09T12:50:10.279Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:02.460

Modified: 2026-09-10T04:18:19.907

Link: CVE-2026-87460

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-09T00:09:35Z

Links: CVE-2026-87460 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T09:15:16Z

Weaknesses