Description
Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Google Chrome versions prior to 153.0.8010.36 contain a use‑after‑free flaw in the Passwords component. The defect allows a remote attacker to exploit social‑engineering techniques to trigger a UI interaction that can execute arbitrary code outside the browser sandbox. The vulnerability is a classic memory‑management error that compromises both confidentiality and integrity of the system with potential system‑wide impact.

Affected Systems

The flaw affects all installations of Google Chrome built before version 153.0.8010.36. Any user who has not upgraded past this release is potentially exposed.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known active exploitation at the time of analysis. Chromium rates the issue as a medium severity bug, but the ability to deliver code outside the sandbox elevates the risk. Likely exploitation would require a user to interact with a crafted UI element, making social engineering a necessary precondition. The CVSS score of 9.6 indicates this vulnerability is critically severe.

Generated by OpenCVE AI on September 9, 2026 at 17:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later.
  • Ensure that all user devices run the updated Chrome release as soon as it becomes available.
  • Conduct user training to recognize and avoid social‑engineering attempts that could drive accidental interaction with malicious UI elements.

Generated by OpenCVE AI on September 9, 2026 at 17:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Title Use After Free in Passwords Allows Remote Code Execution via UI Interaction

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Use After Free in Passwords Allows Remote Code Execution via UI Interaction

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:55:40.532Z

Reserved: 2026-09-08T22:39:30.400Z

Link: CVE-2026-87526

cve-icon Vulnrichment

Updated: 2026-09-09T13:29:29.241Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:09.853

Modified: 2026-09-10T04:18:23.773

Link: CVE-2026-87526

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T09:45:06Z

Weaknesses