Description
Information leak in WebMCP in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure via cross‑origin data leak
Action: Update Chrome
AI Analysis

Impact

Information leak in the WebMCP component of Google Chrome prior to version 153.0.8010.36 allows a remote attacker who has already compromised the renderer process to retrieve cross‑origin data by serving a specially crafted HTML page. The flaw is a classic information‑disclosure vulnerability that can expose sensitive content to a malicious script running in a different origin. The impact is limited to victims whose renderer process has been compromised, but once compromised it permits pervasive data extraction across origins.

Affected Systems

All installations of Google Chrome with a stable channel version earlier than 153.0.8010.36 are affected. This includes Windows, macOS, Linux and other platforms that ship the stable channel of Chrome without the WebMCP patch. Newer revisions of Chrome, starting with 153.0.8010.36 and beyond, contain the fix and are not vulnerable.

Risk and Exploitability

The EPSS score is 0.00241, indicating an extremely low likelihood, and the vulnerability is not listed in the CISA KEV catalog, indicating a moderate baseline risk. However, the attack requires that an adversary can execute code inside the renderer process, which typically requires exploitation of another vulnerability or social‑engineering techniques. The CVSS score is 3.1, indicating a low level of severity, but the Chromium severity is Medium. Overall, the risk is contingent on the ability to compromise the renderer; if that is achieved, the attacker can exfiltrate cross‑origin data with a moderate to high potential impact.

Generated by OpenCVE AI on September 9, 2026 at 19:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later
  • Ensure automatic updates are enabled so that the latest security patches are applied promptly
  • If custom renderer configurations are used, limit exposure by disabling WebMCP‑related features or enforcing strict CSP headers

Generated by OpenCVE AI on September 9, 2026 at 19:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Title WebMCP Information Leak Enabling Cross‑Origin Data Exfiltration in Google Chrome

Wed, 09 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title WebMCP Information Leak Enabling Cross‑Origin Data Exfiltration in Google Chrome

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Information leak in WebMCP in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T15:07:42.861Z

Reserved: 2026-09-08T22:39:23.905Z

Link: CVE-2026-87521

cve-icon Vulnrichment

Updated: 2026-09-09T15:07:23.868Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:09.243

Modified: 2026-09-09T18:02:53.943

Link: CVE-2026-87521

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T23:30:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor