Description
Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The flaw is a numeric truncation error in Chrome’s Media component that can be triggered by a crafted HTML page. When the truncated value is processed, the browser may execute arbitrary code outside the sandbox, granting the attacker the privileges of the browser process. This weakness is classified as CWE‑197, where improper handling of numeric values can lead to loss of precision and unexpected behavior. Although Chromium labels the severity as medium, the sandbox escape elevates the overall risk to a critical level.

Affected Systems

The vulnerability affects Google Chrome browsers on the stable channel that are older than version 153.0.8010.36. It is present on all desktop installations of Chrome released before the update, regardless of operating system. Users running earlier releases are potentially vulnerable when they load a malicious HTML file from an untrusted source.

Risk and Exploitability

The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, but the CVSS score of 9.6 denotes a critical risk. The most likely attack vector is a modified HTML page served over the web or delivered via a local file that the user opens; this inference is based on the description that a crafted HTML file can trigger the defect. Once the page renders, the truncation error can cause the browser process to execute unauthorized code, potentially allowing the attacker to run commands with the privileges of the user—effectively achieving system‑level compromise. No additional mitigation is available beyond updating the browser, so rapid patching is essential.

Generated by OpenCVE AI on September 9, 2026 at 17:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later, which includes proper bounds checking for media numeric values.
  • Configure enterprise update policies to enforce automatic updates, ensuring the latest stable release is installed as soon as it is released.
  • Until the update arrives, restrict users from opening unknown or untrusted HTML files and consider implementing a stricter content security policy that limits media from untrusted sources.

Generated by OpenCVE AI on September 9, 2026 at 17:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Media Component Numeric Truncation in Chrome

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Media Component Numeric Truncation in Chrome

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-197
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:55:45.192Z

Reserved: 2026-09-08T22:39:34.576Z

Link: CVE-2026-87529

cve-icon Vulnrichment

Updated: 2026-09-09T13:29:46.549Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:10.240

Modified: 2026-09-10T04:18:24.343

Link: CVE-2026-87529

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T09:45:06Z

Weaknesses