Description
Observable discrepancy in Layout in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via Layout Discrepancy
Action: Apply Update
AI Analysis

Impact

The vulnerability allows a remote attacker to induce Chrome to render a page layout in a way that leaks sensitive information from the page. By serving a crafted HTML page, an attacker can cause the browser to expose data without requiring authentication or local execution. This weakness is classified as CWE-203 and CWE-204, where unauthorized access to a permitted resource occurs.

Affected Systems

The affected software is Google Chrome. All versions released prior to 153.0.8010.36 are vulnerable. The vendor’s release notes indicate that the issue is fixed in the stable channel update that contains 153.0.8010.36.

Risk and Exploitability

The CVSS score for this issue is 5.3, and the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog. An attacker must host or deliver a malicious web page that exploits the layout discrepancy to extract data. While the current exploitation probability appears low, the medium severity and the fact that the flaw can be triggered by simply loading a page mean that the risk to environments that rely on Chrome for sensitive browsing is noteworthy. The primary attack vector is likely phishing or other malicious websites that can serve crafted HTML.

Generated by OpenCVE AI on September 9, 2026 at 19:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Chrome update (153.0.8010.36 or newer) to eliminate the layout discrepancy.
  • Enable Safe Browsing in strict mode or apply content‑security‑policy settings that limit local resource access for untrusted content until a patch is available.
  • Use monitoring or developer tools to detect anomalous data leaks caused by page layout and isolate affected clients if leaks are observed.

Generated by OpenCVE AI on September 9, 2026 at 19:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Wed, 09 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Chrome Layout Discrepancy Allows Remote Information Disclosure chromium-browser: chromium-browser: Observable discrepancy in Layout
Weaknesses CWE-204
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Wed, 09 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Chrome Layout Discrepancy Allows Remote Information Disclosure

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Observable discrepancy in Layout in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-203
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T15:03:15.601Z

Reserved: 2026-09-08T22:40:58.260Z

Link: CVE-2026-87566

cve-icon Vulnrichment

Updated: 2026-09-09T15:03:08.887Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:14.303

Modified: 2026-09-09T19:18:03.733

Link: CVE-2026-87566

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-09T00:09:58Z

Links: CVE-2026-87566 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T23:00:15Z

Weaknesses
  • CWE-203

    Observable Discrepancy

  • CWE-204

    Observable Response Discrepancy