Description
Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)
Published: 2026-09-09
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution inside browser sandbox via malicious extension
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a memory corruption flaw in the V8 JavaScript engine of Google Chrome prior to version 153.0.8010.36. When a specially crafted Chrome extension is loaded, a remote attacker could trigger the fault and potentially execute arbitrary code within the browser’s sandbox. This flaw falls under CWE‑119, a classic buffer overflow that compromises data integrity and can be leveraged for remote code execution.

Affected Systems

The affected product is Google Chrome on desktop systems. Any installation of Chrome at or below version 153.0.8010.36 is vulnerable. The security advisory is for the stable channel; earlier channels may have higher versions, but the vulnerability specifically applies to the referenced build range.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity, while the EPSS score of <1% suggests low exploitation probability. The KEV catalog does not list this vulnerability, indicating it is not widely used by threat actors yet. However, the exploit path remains viable: a malicious extension could be distributed via the Chrome Web Store or other channels, though this distribution channel is inferred from typical extension distribution practices, meaning users who install untrusted extensions may be at risk. The absence of a known patch until the new release means the window for exploitation exists until the update is applied.

Generated by OpenCVE AI on September 9, 2026 at 16:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later.
  • Uninstall or disable all untrusted or unnecessary Chrome extensions.
  • Restrict extension installations to the Chrome Web Store and review permissions before installing new extensions.

Generated by OpenCVE AI on September 9, 2026 at 16:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Memory Corruption in Chrome's V8 Engine from a Malicious Extension

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Memory Corruption in Chrome's V8 Engine from a Malicious Extension

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)
Weaknesses CWE-119
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:55:33.319Z

Reserved: 2026-09-08T22:38:28.971Z

Link: CVE-2026-87489

cve-icon Vulnrichment

Updated: 2026-09-09T12:57:24.680Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:05.663

Modified: 2026-09-10T04:18:21.650

Link: CVE-2026-87489

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T12:30:07Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer