Description
Uninitialized resource in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Disclosure
Action: Immediate Patch
AI Analysis

Impact

An uninitialized resource in Chrome's codec implementation allows a remote attacker to read memory inside the browser sandbox. The flaw, classified as CWE‑908 and CWE‑824, could expose sensitive data or enable further exploitation by leaking information that is normally protected by the sandbox.

Affected Systems

Google Chrome browsers with version numbers earlier than 153.0.8010.36 are affected. This includes all stable channel releases released before the update noted in the official Chrome release blog.

Risk and Exploitability

The vulnerability has a CVSS score of 4.3, indicating medium severity. An attacker can exploit it by serving a crafted HTML page to a user who opens it in the affected browser. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog. Since the exploit requires a page with malicious content, the risk remains medium until the affected versions are removed from use.

Generated by OpenCVE AI on September 9, 2026 at 13:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later.
  • Ensure that automatic updates are enabled so future patches are applied promptly.
  • Avoid browsing untrusted web content or consider restricting sandboxed content until the update is installed.

Generated by OpenCVE AI on September 9, 2026 at 13:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Thu, 10 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Resource in Chrome Codecs Enables Sandbox Memory Leak chromium-browser: chromium-browser: Uninitialized resource in Codecs
Weaknesses CWE-824
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

threat_severity

Moderate


Wed, 09 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Title Uninitialized Resource in Chrome Codecs Enables Sandbox Memory Leak

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Uninitialized resource in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-908
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T20:03:46.386Z

Reserved: 2026-09-08T22:38:48.843Z

Link: CVE-2026-87497

cve-icon Vulnrichment

Updated: 2026-09-09T19:47:10.275Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:06.563

Modified: 2026-09-10T19:21:15.023

Link: CVE-2026-87497

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-09T00:09:45Z

Links: CVE-2026-87497 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T04:15:15Z

Weaknesses
  • CWE-824

    Access of Uninitialized Pointer

  • CWE-908

    Use of Uninitialized Resource