Description
Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read memory outside the sandbox via a local program. (Chromium security severity: High)
Published: 2026-09-09
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Local memory read outside sandbox via Chrome Chromoting
Action: Apply Patch
AI Analysis

Impact

An out‑of‑bounds read occurs in the Chromoting component of Google Chrome for Windows before version 153.0.8010.36. The flaw allows a local attacker to read memory locations that lie outside the Sandbox boundary through a local program, potentially exposing sensitive information stored in process memory. The CVE is rated High in Chromium severity, reflecting the seriousness of the data disclosure risk, although it does not provide a pathway to remote code execution.

Affected Systems

Google Chrome on Windows installations running any version earlier than 153.0.8010.36 are affected. The vulnerability is limited to Windows platforms and does not impact Chrome running on other operating systems.

Risk and Exploitability

The CVSS score of 2.7 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation under normal circumstances. The vulnerability is not listed in the CISA KEV catalog. The flaw allows a local attacker with access to a victim’s machine to execute a local program that interacts with Chrome’s Chromoting interface and read memory addresses beyond the sandbox boundary. No remote attack vector is documented, so the attack requires local presence and a program that can communicate with Chrome. While the risk to overall system compromise is limited, the capability to read arbitrary memory could expose sensitive data, making it a data disclosure risk. Updating to Chrome 153.0.8010.36 or newer eliminates the flaw.

Generated by OpenCVE AI on September 9, 2026 at 21:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Chrome update (153.0.8010.36 or newer).
  • If immediate update is not possible, disable the Chromoting feature via Chrome Enterprise policy or the local extensions settings until the patch is applied.
  • Apply local execution restrictions or privileged access controls to limit the ability of untrusted programs to communicate with Chrome’s Chromoting interface.

Generated by OpenCVE AI on September 9, 2026 at 21:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows

Thu, 10 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Local memory read via Chrome Chromoting out‑of‑bounds read in Windows

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Wed, 09 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Local memory read via Chrome Chromoting out‑of‑bounds read in Windows

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read memory outside the sandbox via a local program. (Chromium security severity: High)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-17T17:53:19.240Z

Reserved: 2026-09-08T22:39:29.195Z

Link: CVE-2026-87525

cve-icon Vulnrichment

Updated: 2026-09-09T20:00:20.523Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:09.733

Modified: 2026-09-10T19:23:32.703

Link: CVE-2026-87525

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T16:00:13Z

Weaknesses