Description
Interpretation conflict in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted file. (Chromium security severity: Low)
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Bypass of System Access Restrictions
Action: Update Browser
AI Analysis

Impact

An interpretation conflict in the SafeBrowsing subsystem of Google Chrome on macOS allows a remote attacker to bypass local system access restrictions by delivering a specially crafted file. The flaw permits the circumvents expected safeguards, granting the victim’s user privileges that should have been blocked. The vulnerability is classified as CWE‑436, indicating a problem with data interpretation or handling. The maximum damage is limited to the rights of the account that executes the file, though repeated exposure could enable persistent access to local resources.

Affected Systems

Google Chrome running on macOS where the installed version is older than 153.0.8010.36. No specific sub‑version ranges are listed, only the prerelease cutoff before the final patch. Any older stable channel releases on the platform are potentially vulnerable.

Risk and Exploitability

The EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. The CVSS score of 6.5 suggests moderate severity, while the Chromium security severity is noted as low. A successful attack requires convincing a user to open a maliciously crafted file, after which the SafeBrowsing interpretation conflict permits local access to otherwise restricted resources. The risk is therefore confined to environments where users may be targeted by phishing or other social engineering tactics.

Generated by OpenCVE AI on September 21, 2026 at 04:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later to receive the SafeBrowsing patch.
  • Enable Chrome’s Safe Browsing enterprise policy to enforce active protection against malicious files in corporate or managed settings.
  • Educate users to avoid opening files from untrusted sources and to report suspicious attachments promptly.

Generated by OpenCVE AI on September 21, 2026 at 04:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Mon, 21 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Title SafeBrowsing Interpretation Conflict Enables Remote Bypass of System Access on macOS

Mon, 14 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Interpretation conflict in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted file. (Chromium security severity: Low)
Weaknesses CWE-436
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-14T12:37:42.434Z

Reserved: 2026-09-08T22:43:06.274Z

Link: CVE-2026-87627

cve-icon Vulnrichment

Updated: 2026-09-14T12:37:37.456Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:20.987

Modified: 2026-09-14T21:43:11.470

Link: CVE-2026-87627

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:00:14Z

Weaknesses