Description
Cross-site scripting in SanitizerAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Origin Policy Bypass via XSS
Action: Update Browser
AI Analysis

Impact

The vulnerability is a cross‑site scripting flaw in Chrome’s SanitizerAPI that allows an attacker to inject crafted HTML and bypass the browser’s web‑origin policy. This flaw falls under CWE‑79 and can enable a remote attacker to execute arbitrary script in the context of a trusted web origin, potentially exposing confidential data or hijacking the user’s session.

Affected Systems

Google Chrome versions prior to 153.0.8010.36 are impacted. Any system deploying these affected Chrome releases is susceptible until it is updated to a fixed version.

Risk and Exploitability

The flaw has a CVSS score of 4.3, denoting medium severity. Exploitation requires an attacker to host a malicious HTML page that a user visits; no local privilege escalation is needed. The EPSS score is < 1% and it is not listed in the CISA KEV catalog, indicating that public exploitation is currently unlikely but not impossible. Given the nature of the attack vector, the risk is moderate and should be addressed promptly.

Generated by OpenCVE AI on September 9, 2026 at 19:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome version 153.0.8010.36 or later.
  • Configure enterprise policy to disable or restrict use of the SanitizerAPI feature if possible.
  • Implement a strict Content Security Policy on exposed web applications to mitigate XSS impact.

Generated by OpenCVE AI on September 9, 2026 at 19:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting via SanitizerAPI in Google Chrome

Wed, 09 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting via SanitizerAPI in Google Chrome

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Cross-site scripting in SanitizerAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-79
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T17:25:25.319Z

Reserved: 2026-09-08T22:43:24.930Z

Link: CVE-2026-87632

cve-icon Vulnrichment

Updated: 2026-09-09T17:25:06.782Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:21.550

Modified: 2026-09-09T20:21:22.320

Link: CVE-2026-87632

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:00:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')