Description
Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Apply Patch
AI Analysis

Impact

Information leak in Google Chrome's Core component prior to version 153.0.8010.36 allows a remote attacker to exfiltrate sensitive information from a victim’s system when the victim opens a specially crafted HTML page. The flaw exploits Core’s handling of sensitive data, exposing information such as cookies, form inputs, or cached files. This type of vulnerability is classified as a data‑exposure weakness (CWE‑200) and can compromise the confidentiality of user information, but it does not provide code execution or privilege escalation.

Affected Systems

Affected users run Google Chrome on any platform supported by the stable channel when the browser version is earlier than 153.0.8010.36. The issue does not affect later releases.

Risk and Exploitability

The CVSS score, 6.5, places this issue in the Medium severity range. The EPSS score is less than 1%, indicating a very low probability of exploitation, and it is not listed in the CISA KEV catalog. Chromium classifies the issue as Low severity. The attack vector requires a remote victim to load a malicious webpage; the flaw does not grant code execution but can expose confidential data, enabling credential theft or privacy violations. Although widespread exploitation is unlikely, the impact on confidentiality warrants timely patching.

Generated by OpenCVE AI on September 9, 2026 at 18:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or newer.
  • Ensure automatic updates are enabled so future security patches are applied promptly.
  • Until the patch is applied, avoid visiting untrusted or unfamiliar websites and consider disabling or restricting extensions that can read browser data.

Generated by OpenCVE AI on September 9, 2026 at 18:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Chromium Core Information Leak via Crafted HTML Page

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Chromium Core Information Leak via Crafted HTML Page

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T15:04:43.368Z

Reserved: 2026-09-08T22:38:10.755Z

Link: CVE-2026-87477

cve-icon Vulnrichment

Updated: 2026-09-09T15:04:13.521Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:04.323

Modified: 2026-09-09T17:15:26.053

Link: CVE-2026-87477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:55:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor