Description
Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution outside the Chrome sandbox by a local attacker
Action: Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free in the Chrome DevTools component that allows a local attacker to run arbitrary code outside the browser sandbox when a local program interacts with DevTools. The flaw is related to missing memory safety checks and is categorized as CWE‑416. As a result, the attacker can compromise the host system with the privileges of the user running the affected Chrome installation.

Affected Systems

Google Chrome desktop versions released before 153.0.8010.36 are affected. The vendor has addressed the issue in the 153.0.8010.36 release and later builds.

Risk and Exploitability

The CKV exploit is local – it requires the attacker to run a program on the target machine that can open or establish a connection to DevTools. The CVSS score is 8.1. The EPSS score indicates that the probability of exploitation is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. Chromium rates the issue as Medium severity. Because the attack vector is purely local, the practical risk depends on the local environment and user privileges, but once exploited, the attacker can execute any code with user rights.

Generated by OpenCVE AI on September 9, 2026 at 18:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to Chrome 153.0.8010.36 or later.
  • Avoid running untrusted local applications that can trigger the Chrome DevTools interface until after the patch has been applied.
  • Segregate browsing activity from local development tools by using a dedicated user profile or virtual machine to reduce exposure to the vulnerable component.

Generated by OpenCVE AI on September 9, 2026 at 18:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Local use‑after‑free in Chrome DevTools allows arbitrary code execution

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Local use‑after‑free in Chrome DevTools allows arbitrary code execution

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:56:24.912Z

Reserved: 2026-09-08T22:39:40.102Z

Link: CVE-2026-87533

cve-icon Vulnrichment

Updated: 2026-09-09T14:17:40.963Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:10.707

Modified: 2026-09-10T18:34:50.483

Link: CVE-2026-87533

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T09:45:06Z

Weaknesses