Description
Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)
Published: 2026-09-09
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a memory corruption flaw in the V8 JavaScript engine of Google Chrome prior to version 153.0.8010.36. When a specially crafted Chrome extension is loaded, a remote attacker could trigger the fault and potentially execute arbitrary code within the browser’s sandbox. This flaw falls under CWE‑119, a classic buffer overflow that compromises data integrity and can be leveraged for remote code execution.

Affected Systems

The affected product is Google Chrome on desktop systems. Any installation of Chrome at or below version 153.0.8010.36 is vulnerable. The security advisory is for the stable channel; earlier channels may have higher versions, but the vulnerability specifically applies to the referenced build range.

Risk and Exploitability

The issue is rated as a low severity in Chromium’s own security chart, and no published EPSS score is available, indicating a lack of confirmed exploitation activity. The KEV catalog does not list this vulnerability, suggesting it is not widely used by threat actors yet. However, the exploit path remains viable: a malicious extension could be distributed via the Chrome Web Store or other channels, though this distribution channel is inferred from typical extension distribution practices, meaning users who install untrusted extensions may be at risk. The absence of a known patch until the new release means the window for exploitation exists until the update is applied.

Generated by OpenCVE AI on September 9, 2026 at 05:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later.
  • Uninstall or disable all untrusted or unnecessary Chrome extensions.
  • Restrict extension installations to the Chrome Web Store and review permissions before installing new extensions.

Generated by OpenCVE AI on September 9, 2026 at 05:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Memory Corruption in Chrome's V8 Engine from a Malicious Extension

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Memory corruption in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)
Weaknesses CWE-119
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T00:10:05.725Z

Reserved: 2026-09-08T22:38:28.971Z

Link: CVE-2026-87489

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T01:17:05.663

Modified: 2026-09-09T01:17:05.663

Link: CVE-2026-87489

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T05:30:05Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer