Description
Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Memory Disclosure
Action: Apply Patch
AI Analysis

Impact

An out‑of‑bounds read bug in ANGLE allows a remote attacker to read memory outside the sandbox by delivering a crafted HTML page. This vulnerability can expose sensitive data but does not provide code execution or denial of service.

Affected Systems

Google Chrome is affected in all releases prior to 153.0.8010.36. Users running older versions are vulnerable until an update is installed.

Risk and Exploitability

The flaw can be triggered over the internet by loading a malicious page. The CVSS score of 4.3 marks it as Medium severity, and the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA KEV. The Chromium severity rating is medium, indicating a moderate risk if the affected browser is enabled in a user’s environment.

Generated by OpenCVE AI on September 9, 2026 at 22:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later.
  • If an upgrade cannot be performed immediately, restrict the browser from opening untrusted HTML content or use site‑wide security policies to block potentially malicious content.
  • Ensure automatic browser updates are enabled to receive future patches promptly.

Generated by OpenCVE AI on September 9, 2026 at 22:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in ANGLE Allowing Remote Memory Leak

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Wed, 09 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in ANGLE Allowing Remote Memory Leak

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-17T17:52:00.634Z

Reserved: 2026-09-08T22:41:31.017Z

Link: CVE-2026-87586

cve-icon Vulnrichment

Updated: 2026-09-09T19:46:26.219Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:16.463

Modified: 2026-09-10T13:47:20.340

Link: CVE-2026-87586

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T11:45:11Z

Weaknesses