Description
Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote System Access Bypass
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from an improper state validation step in Chrome’s Safe Browsing module. A remote attacker can craft a malicious HTML page that exploits this flaw to bypass system access restrictions enforced by Safe Browsing, enabling unauthorized control over the affected system. This flaw falls under CWE‑754 and represents a weakness in access control that can breach system integrity.

Affected Systems

The flaw affects Google Chrome browsers before version 153.0.8010.36. All desktop builds within this version range are vulnerable until updated to the newer stable channel release.

Risk and Exploitability

The CVE lists a medium severity with a CVSS score of 6.5, and the EPSS score is below 1%, indicating a low probability of exploitation. It is not in the CISA KEV catalog, meaning there is no confirmed exploitation yet. The most likely attack vector is a crafted HTML page delivered to the victim’s browser, requiring no authentication or elevated privileges beyond the user’s Chrome session.

Generated by OpenCVE AI on September 10, 2026 at 17:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 153.0.8010.36 or later to eliminate the flaw.
  • Configure enterprise or group policy to enforce automatic updates for Chrome to prevent re‑exposure.
  • If upgrading is delayed, consider disabling or restricting Safe Browsing or removing browser permissions that enable local file access from web pages as a temporary mitigation.

Generated by OpenCVE AI on September 10, 2026 at 17:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Thu, 10 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title Chrome Safe Browsing State Validation Flaw Enabling System Access Bypass

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Chrome Safe Browsing State Validation Flaw Enabling System Access Bypass

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-754
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T14:44:29.371Z

Reserved: 2026-09-08T22:39:38.877Z

Link: CVE-2026-87532

cve-icon Vulnrichment

Updated: 2026-09-10T14:43:59.202Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:10.600

Modified: 2026-09-10T18:33:53.663

Link: CVE-2026-87532

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:00:06Z

Weaknesses
  • CWE-754

    Improper Check for Unusual or Exceptional Conditions