Description
Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A use‑after‑free flaw in the handling of browser extensions in Google Chrome on macOS allows an attacker to execute arbitrary code outside the browser sandbox through a crafted HTML page. The vulnerability is a classic use‑after‑free (CWE‑416) and can result in remote code execution with the privileges of the user who launches Chrome. The flaw emerges when Chrome frees memory associated with an extension before it is repurposed, leaving a dangling pointer that a malicious web page can exploit. The likely attack vector is a malicious site that serves the crafted page; based on the description, it is inferred that the attacker does not need elevated privileges or authentication besides convincing the user to load the malicious content.

Affected Systems

The vulnerability affects users running Google Chrome on macOS who are on the stable channel and have version numbers less than 153.0.8010.36. Only macOS builds are impacted; versions for Windows or Linux are not affected. The fix is included in Chrome 153.0.8010.36 and later releases.

Risk and Exploitability

The CVSS score of 9.6 indicates a severe risk, and the EPSS score of < 1% suggests a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack can be performed by visiting a malicious web page, with no authentication or privileged access required. The exploitation would allow the attacker to run code with the privileges of the user’s Chrome session. The attack requires no additional software, only the delivery of the crafted HTML, thereby making the threat relatively straightforward for a determined attacker.

Generated by OpenCVE AI on September 9, 2026 at 18:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later.
  • If an immediate update cannot be performed, disable or uninstall all Chrome extensions to remove the vulnerable code paths.
  • Enable Chrome’s safe browsing protection and block extensions from unknown sources until an update is available.

Generated by OpenCVE AI on September 9, 2026 at 18:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Use-After-Free in Chrome Extensions on macOS

Wed, 09 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Google
Google chrome

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Use-After-Free in Chrome Extensions on macOS

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Use after free in Extensions in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:55:41.950Z

Reserved: 2026-09-08T22:43:35.068Z

Link: CVE-2026-87637

cve-icon Vulnrichment

Updated: 2026-09-09T13:29:49.912Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:22.103

Modified: 2026-09-10T04:18:30.550

Link: CVE-2026-87637

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T10:30:04Z

Weaknesses