Description
Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

Improper input validation in Chrome's SiteIsolation allows a remote attacker who has already compromised the renderer process to potentially execute arbitrary code outside the sandbox through a crafted HTML page, jeopardizing system confidentiality, integrity, and availability. The flaw is a classic input validation weakness (CWE-20).

Affected Systems

The vulnerability affects Google Chrome browsers running versions prior to 153.0.8010.36. Users of older releases are directly exposed until an update is applied.

Risk and Exploitability

Chromium grades this issue with a CVSS score of 8.3 (High), an EPSS score of <1%, and no KEV listing, indicating the exploitation risk is currently unknown but nonzero. The likely attack vector requires remote code that first compromises a renderer process, potentially via malicious web content; once inside, the attacker can escape the sandbox to run code with the renderer's privileges. No evidence suggests that the flaw is publicly exploitable at present, but the lack of a KEV listing means it may be in an early stage of exploitation or yet undisclosed. Organizations should anticipate a moderate threat level pending further evidence. They should treat the vulnerability as a high-priority patch candidate due to the potential for full system compromise.

Generated by OpenCVE AI on September 9, 2026 at 17:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 153.0.8010.36 or later to obtain the SiteIsolation input validation fix.
  • If an immediate update is not possible, temporarily disable SiteIsolation by setting the corresponding enterprise policy or chrome://flags value to reduce the attack surface until the patch is applied.
  • Monitor for anomalous renderer process behavior and outbound connections using security tools; investigate any suspicious activity to detect potential exploitation attempts.

Generated by OpenCVE AI on September 9, 2026 at 17:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Title Renderer Process Escalation via Improper SiteIsolation Input Validation in Chrome

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:56:14.293Z

Reserved: 2026-09-08T22:40:26.565Z

Link: CVE-2026-87553

cve-icon Vulnrichment

Updated: 2026-09-09T14:13:29.311Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:12.900

Modified: 2026-09-10T04:18:25.927

Link: CVE-2026-87553

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T12:15:16Z

Weaknesses
  • CWE-20

    Improper Input Validation