Description
Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via DevTools injection
Action: Immediate Patch
AI Analysis

Impact

Injection within the DevTools component of Google Chrome permits an attacker who has already compromised the renderer process to execute arbitrary code outside the browser sandbox. This is a CWE‑74 input injection flaw. The flaw exists before Chrome version 153.0.8010.36, and the CVE description characterizes it as a high‑severity issue.

Affected Systems

All Google Chrome browsers older than 153.0.8010.36 are affected. Users of these releases should consider upgrading to remediate the vulnerability.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability is not listed in CISA KEV. The CVSS score is 8.3. Exploitation requires an initial compromise of the renderer process; the attacker can then supply a malicious HTML page that triggers the DevTools injection. Because the flaw enables execution outside the sandbox, it poses a serious threat if the prerequisite conditions are met.

Generated by OpenCVE AI on September 9, 2026 at 17:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later
  • If upgrading is not possible, restrict DevTools access for all users who do not require it
  • Monitor logs for abnormal DevTools activity and signs of renderer process compromise

Generated by OpenCVE AI on September 9, 2026 at 17:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title DevTools Injection in Google Chrome Allows Remote Code Execution

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title DevTools Injection in Google Chrome Allows Remote Code Execution

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-74
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:56:18.494Z

Reserved: 2026-09-08T22:41:04.693Z

Link: CVE-2026-87572

cve-icon Vulnrichment

Updated: 2026-09-09T14:14:17.185Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:14.943

Modified: 2026-09-10T04:18:26.480

Link: CVE-2026-87572

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T10:00:06Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')