Description
Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Code Execution
Action: Apply Patch
AI Analysis

Impact

The vulnerability is caused by an uncontrolled search path element in the CredentialProvider component of Google Chrome on Windows. A local attacker who can run arbitrary programs can manipulate the search path so that Chrome loads and executes malicious DLLs, enabling code execution outside the Chrome sandbox. The weakness corresponds to CWE-427 (Uncontrolled Search Path Element) and is documented as having medium severity by the Chromium security team.

Affected Systems

Windows operating systems running Google Chrome versions prior to 153.0.8010.36 are affected. Update to Chrome 153.0.8010.36 or later, which includes the security fix, to eliminate the flaw.

Risk and Exploitability

The advisory now indicates a CVSS score of 8.1, which corresponds to high severity. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating limited known exploitation or absence of reported attacks. Because this flaw requires a local attacker with the ability to execute programs, it would likely be exploited only after the attacker has gained local access or user credentials. As such, the risk of exploitation is moderate. Patching is strongly recommended.

Generated by OpenCVE AI on September 9, 2026 at 18:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.36 or later.
  • Configure operating‑system policies to restrict non‑admin users from loading unsigned DLLs into Chrome’s process space.
  • Monitor system activity for unexpected DLL loads or command executions that could signal exploitation attempts.

Generated by OpenCVE AI on September 9, 2026 at 18:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Local Code Execution via Uncontrolled Search Path in Chrome CredentialProvider

Wed, 09 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome
Microsoft
Microsoft windows

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Local Code Execution via Uncontrolled Search Path in Chrome CredentialProvider

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
Weaknesses CWE-427
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:56:25.651Z

Reserved: 2026-09-08T22:39:36.090Z

Link: CVE-2026-87530

cve-icon Vulnrichment

Updated: 2026-09-09T14:18:58.121Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:10.360

Modified: 2026-09-10T04:18:24.527

Link: CVE-2026-87530

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T09:45:06Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element