Description
Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A use‑after‑free flaw exists in the V8 JavaScript engine of Google Chrome prior to version 153.0.8010.36. This vulnerability allows a remote attacker to execute arbitrary code inside Chrome’s sandbox by loading a specially crafted HTML page. It is classified as a high‑severity memory corruption issue and is a classic example of a use‑after‑free condition leading to code execution.

Affected Systems

The issue affects all users running Google Chrome versions older than 153.0.8010.36; any system with this build exposed to web content is potentially vulnerable.

Risk and Exploitability

The vulnerability is a remote code execution flaw that permits a remote attacker to execute arbitrary code inside Chrome’s sandbox by loading a crafted HTML page. The exploit requires only that the victim open the malicious page; no other privileged actions are documented. The CVSS score of 8.8 indicates a high severity, and the EPSS score of <1% shows a very low exploitation probability. The issue is not listed in the CISA KEV catalog, and no publicly available exploit code is referenced in the CVE description.

Generated by OpenCVE AI on September 9, 2026 at 17:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later to apply the V8 fix.
  • Restrict or disable JavaScript execution through Chrome policy until the update can be deployed.
  • Remain vigilant by monitoring Chrome security releases and applying subsequent patches promptly.

Generated by OpenCVE AI on September 9, 2026 at 17:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Use‑After‑Free in Chrome V8

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Use‑After‑Free in Chrome V8

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:55:24.595Z

Reserved: 2026-09-08T22:39:48.165Z

Link: CVE-2026-87536

cve-icon Vulnrichment

Updated: 2026-09-09T12:47:34.454Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:11.047

Modified: 2026-09-10T18:41:00.003

Link: CVE-2026-87536

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T10:00:06Z

Weaknesses