Description
Use after free in Chromecast in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A use-after-free condition in Chromecast functionality within Google Chrome allows a remote attacker to execute arbitrary code inside the browser sandbox by delivering a crafted HTML page. This flaw is a classic memory corruption weakness (CWE‑416) and also maps to an improper resource operation weakness (CWE‑825), compromising the confidentiality, integrity, and availability of the affected system by running malicious payloads with reduced privileges but still capable of bypassing sandbox restrictions.

Affected Systems

All users running Google Chrome versions earlier than 153.0.8010.36 are vulnerable. The issue impacts the native Chromecast component used for media casting and is present in the Chrome stable channel on desktop platforms.

Risk and Exploitability

Because the vulnerability requires a crafted HTML page and can be triggered remotely, it can be exploited by a malicious website or phishing email that loads the page in Chrome. The CVSS score of 8.8 indicates high severity, but the EPSS score is not reported; the flaw is not listed in the CISA KEV catalog. Inferred attack scenarios involve a malicious web actor hosting a specially crafted page, exploiting the out‑of‑bounds access to trigger code execution within the sandbox. The lack of a publicly disclosed exploit means the current threat level is moderate, yet the ability to achieve remote code execution warrants prompt mitigation.

Generated by OpenCVE AI on September 9, 2026 at 13:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Chrome to version 153.0.8010.36 or later, which contains the memory‑management fix that eliminates the use‑after‑free.
  • If upgrading is delayed, disable Chromecast support by removing the built‑in Chromecast functionality or disabling the related Chrome flag in settings to reduce the attack surface.
  • Apply a robust content security policy to block execution of unexpected scripts and monitor for abnormal HTML content that could exploit memory corruption vulnerabilities.

Generated by OpenCVE AI on September 9, 2026 at 13:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome Chromecast Allows Remote Code Execution via Crafted HTML chromium-browser: chromium-browser: Use after free in Chromecast
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Wed, 09 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome Chromecast Allows Remote Code Execution via Crafted HTML

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Use after free in Chromecast in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:55:23.523Z

Reserved: 2026-09-08T22:41:33.927Z

Link: CVE-2026-87588

cve-icon Vulnrichment

Updated: 2026-09-09T12:47:19.983Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:16.683

Modified: 2026-09-10T04:18:27.700

Link: CVE-2026-87588

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-09T00:09:39Z

Links: CVE-2026-87588 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T10:00:06Z

Weaknesses