Description
Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

Improper input validation in the FileAPI component of Google Chrome allows an attacker who has already compromised the renderer process to execute arbitrary code outside the sandbox. The flaw stems from a failure to sanitize user‑supplied data before it is processed by the FileAPI, giving the attacker a vehicle for code execution once the renderer has been subverted. This is a classic validation or sanitization failure (CWE‑20).

Affected Systems

Google Chrome versions prior to 153.0.8010.36 on all supported platforms are affected. Any installation that has not yet been updated to 153.0.8010.36 or later contains the vulnerable code and may be exploited if the renderer process can be compromised.

Risk and Exploitability

The Chromium advisory now assigns a CVSS score of 8.3, indicating a High severity. The EPSS score is less than 1 percent, reflecting a very low but nonzero probability of exploitation. The vulnerability is not listed in CISA KEV, suggesting no known active exploitation. Exploitation still requires the attacker to already control the renderer process, a high‑barrier scenario. Nevertheless, the potential impact is remote code execution outside the browser sandbox, warranting prompt remediation.

Generated by OpenCVE AI on September 9, 2026 at 17:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.36 or later to eliminate the input‑validation flaw in the FileAPI.
  • Where possible, validate or sanitize all externally supplied HTML before it reaches the browser to maintain strict boundary control, addressing the underlying CWE‑20 weakness.
  • If an immediate browser update is infeasible, isolate the renderer process or restrict untrusted content from reaching it via proxy or local filtering until the vulnerability is remediated.

Generated by OpenCVE AI on September 9, 2026 at 17:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Improper Input Validation in Chrome FileAPI

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Improper Input Validation in Chrome FileAPI

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:56:06.352Z

Reserved: 2026-09-08T22:39:08.990Z

Link: CVE-2026-87510

cve-icon Vulnrichment

Updated: 2026-09-09T14:11:14.021Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:08.053

Modified: 2026-09-10T04:18:22.860

Link: CVE-2026-87510

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T09:45:06Z

Weaknesses
  • CWE-20

    Improper Input Validation