Description
Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Information leak in Google Chrome's Core component prior to version 153.0.8010.36 allows a remote attacker to exfiltrate sensitive information from a victim’s system when the victim opens a specially crafted HTML page. The flaw exploits Core’s handling of sensitive data, exposing information such as cookies, form inputs, or cached files. This type of vulnerability is classified as a data‑exposure weakness (CWE‑200) and can compromise the confidentiality of user information, but it does not provide code execution or privilege escalation.

Affected Systems

Affected users run Google Chrome on any platform supported by the stable channel when the browser version is earlier than 153.0.8010.36. The issue does not affect later releases.

Risk and Exploitability

EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Chromium classifies the issue as Low severity, indicating limited exploitation potential. The attack vector requires a remote victim to load a malicious webpage; the flaw does not grant code execution, but it can expose confidential data, making credential theft or privacy violations possible. While widespread exploitation is unlikely, the risk is considered moderate and should be mitigated promptly.

Generated by OpenCVE AI on September 9, 2026 at 05:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or newer.
  • Ensure automatic updates are enabled so future security patches are applied promptly.
  • Until the patch is applied, avoid visiting untrusted or unfamiliar websites and consider disabling or restricting extensions that can read browser data.

Generated by OpenCVE AI on September 9, 2026 at 05:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Chromium Core Information Leak via Crafted HTML Page

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Information leak in Core in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-200
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T00:10:06.186Z

Reserved: 2026-09-08T22:38:10.755Z

Link: CVE-2026-87477

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T01:17:04.323

Modified: 2026-09-09T01:17:04.323

Link: CVE-2026-87477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T06:00:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor