Description
Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low)
Published: 2026-09-09
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution outside Chrome sandbox via local updater
Action: Apply Patch
AI Analysis

Impact

A local authorization bypass in Google Chrome’s Updater on Windows prior to version 153.0.8010.36 permits a local attacker to run code with system privileges, escaping the browser sandbox. This flaw can allow the attacker to modify system files, install malware, or perform other high‑impact actions on the host. The weakness is classified as CWE-863 (authorization bypass).

Affected Systems

Google Chrome for Windows users running any version before 153.0.8010.36 are affected. Upgrades to 153.0.8010.36 or newer resolve the issue.

Risk and Exploitability

The vulnerability’s CVSS score of 8.1 indicates high severity. It is not listed in CISA KEV and its EPSS score is less than 1%, meaning current exploitation likelihood is very low but the flaw remains high risk if discovered. The attack requires local access; a user with privileges on the target machine can trigger the local updater to run arbitrary code outside Chrome sandbox. Due to lack of public exploits yet, the risk to the broader community remains limited, but the potential impact on the affected system is significant.

Generated by OpenCVE AI on September 9, 2026 at 16:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 153.0.8010.36 or newer
  • Ensure Chrome’s auto‑update feature is enabled so future patches are applied automatically
  • Restrict local user privileges on systems that run Chrome to limit the impact of potential local exploits

Generated by OpenCVE AI on September 9, 2026 at 16:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome
Microsoft
Microsoft windows

Wed, 09 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in Chrome Updater Allows System‑Level Code Execution

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:56:24.177Z

Reserved: 2026-09-08T22:39:07.740Z

Link: CVE-2026-87509

cve-icon Vulnrichment

Updated: 2026-09-09T14:14:19.479Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:07.943

Modified: 2026-09-10T04:18:22.690

Link: CVE-2026-87509

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T12:30:07Z

Weaknesses