Description
Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A use‑after‑free flaw in the DevTools component of Google Chrome allows a remote attacker to execute arbitrary code inside the browser sandbox via a crafted HTML page. The vulnerability is triggered when a victim opens a malicious HTML document that exploits the freed memory in DevTools, enabling a local code execution path even though the attacker does not gain privileges outside the browser sandbox. The described exploit can be leveraged by social engineering techniques to trick users into loading the malicious page.

Affected Systems

Google Chrome is affected. Versions prior to 153.0.8010.36 are vulnerable. No further version details were supplied.

Risk and Exploitability

The CVSS score is 8.8 and the EPSS score is <1%, but Chromium rates the issue as low severity. Exploitation requires a victim to open a crafted HTML page and run DevTools, so the attack vector is remote web content combined with user interaction. The lack of a KEV listing suggests no known widespread exploitation at this time. Nevertheless, because the flaw permits remote code execution, it poses an immediate risk to any user of an affected Chrome build.

Generated by OpenCVE AI on September 9, 2026 at 17:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Chrome to version 153.0.8010.36 or later
  • If an update cannot be performed immediately, disable DevTools via Chrome policy or a user‑controlled extension
  • Avoid opening untrusted HTML files or links that might be crafted to exploit DevTools

Generated by OpenCVE AI on September 9, 2026 at 17:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Use After Free in DevTools Allows Remote Code Execution via Crafted HTML Page
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Use After Free in DevTools Allows Remote Code Execution via Crafted HTML Page

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:55:29.454Z

Reserved: 2026-09-08T22:42:53.818Z

Link: CVE-2026-87617

cve-icon Vulnrichment

Updated: 2026-09-09T12:52:45.822Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:19.840

Modified: 2026-09-10T04:18:29.133

Link: CVE-2026-87617

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T10:30:04Z

Weaknesses