Description
Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution within the sandbox via a use‑after‑free in V8
Action: Immediate Patch
AI Analysis

Impact

A use‑after‑free vulnerability in the V8 engine allows an attacker who can serve a crafted HTML page to execute arbitrary code while the browser is running. Based on the description, it is inferred that the attacker can run malicious code with the privileges of the sandboxed process, which may bypass certain browser mitigation layers and could further exploit the operating system.

Affected Systems

Google Chrome users running versions of the stable channel prior to 153.0.8010.36 are affected. The issue was identified in the V8 engine component of the Chrome browser, which is distributed with all Chrome installations.

Risk and Exploitability

Based on the description, it is inferred that the likelihood of exploitation depends on the existence of phishing or drive‑by sites that can host such content. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog; based on this information, it is inferred that widespread exploitation has not yet been observed. Nonetheless, the CVSS score of 8.8 indicates a High severity level, and the flaw can be leveraged for remote code execution. The attack vector is inferred to be remote via a malicious web page delivered over the internet.

Generated by OpenCVE AI on September 9, 2026 at 17:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 153.0.8010.36 or later to eliminate the use‑after‑free flaw
  • Ensure that automatic browser updates are enabled so future patches are applied promptly
  • For environments that cannot upgrade immediately, restrict untrusted web content by using whitelisting or network‑level controls until the vulnerability is patched

Generated by OpenCVE AI on September 9, 2026 at 17:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Use after free in V8 allows remote code execution within the sandbox

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Use after free in V8 allows remote code execution within the sandbox

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:55:25.813Z

Reserved: 2026-09-08T22:41:32.491Z

Link: CVE-2026-87587

cve-icon Vulnrichment

Updated: 2026-09-09T12:48:16.776Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:16.580

Modified: 2026-09-10T04:18:27.533

Link: CVE-2026-87587

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T12:45:16Z

Weaknesses