Description
Out of bounds read in Tint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Potential memory disclosure inside sandboxed content
Action: Patch
AI Analysis

Impact

Out‑of‑bounds read occurs in the Tint component of Google Chrome, allowing a remote attacker to read memory within the browser’s sandbox. This could expose sensitive internal data of the browsing context but does not permit code execution at this time. The flaw is categorized as CWE‑125 and is rated as low severity by Chromium’s own assessment. The impact is limited to confidentiality compromise of sandboxed content accessed by a crafted HTML page.

Affected Systems

Google Chrome web browsers on all platforms running a version prior to 153.0.8010.36 are affected. Any installation that has not yet updated beyond that release must be considered vulnerable.

Risk and Exploitability

The CVSS score is 4.3, and the EPSS score is < 1%, indicating a low likelihood of widespread exploitation. No known public exploit exists and the vulnerability is not included in CISA’s KEV catalog, suggesting a low likelihood of widespread exploitation. The attack vector is inferred to require delivery of a specially crafted HTML page to the target through a standard web connection, making it theoretically feasible from any remote location that can reach the victim’s browser.

Generated by OpenCVE AI on September 9, 2026 at 22:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the security update for Google Chrome with at least version 153.0.8010.36 on all machines.
  • After installing, restart all Chrome instances to load updated binaries.
  • Configure endpoint protection or browser policies to restrict loading of untrusted or deprecated content, providing an additional mitigation layer until the update fully propagates across all workstations.

Generated by OpenCVE AI on September 9, 2026 at 22:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Out-of-bounds read in Tint may allow memory disclosure within Chrome sandbox

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Wed, 09 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title Out-of-bounds read in Tint may allow memory disclosure within Chrome sandbox

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Out of bounds read in Tint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-17T17:51:30.508Z

Reserved: 2026-09-08T22:41:39.080Z

Link: CVE-2026-87592

cve-icon Vulnrichment

Updated: 2026-09-09T19:46:07.671Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:17.117

Modified: 2026-09-10T13:46:27.630

Link: CVE-2026-87592

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T13:45:16Z

Weaknesses