Description
Out of bounds read in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

An out-of-bounds read vulnerability in the WebView component of Google Chrome on Android allows a remote attacker, once the renderer process has been compromised, to read memory outside the sandbox. The attack payload is delivered via a crafted HTML page and can expose private data stored in memory. The Chromium team rated the severity as medium.

Affected Systems

Any device running Google Chrome for Android versions earlier than 153.0.8010.36 is affected. Updating to Chrome 153.0.8010.36 or later removes the vulnerability. The flaw resides in the WebView rendering engine used by Chrome on Android.

Risk and Exploitability

Although the EPSS score is low at 0.00225 (about 0.2 %), indicating a low but non‑zero likelihood of exploitation, the CVSS score remains 6.1, which is medium severity. The vulnerability requires a compromised renderer process and is delivered via a crafted HTML page, so exploitation is not trivial. Attackers can conduct the attack remotely by hosting malicious content that the browser renders, resulting in an out‑of‑bounds read that could expose sensitive data in memory. The risk to users is primarily the exposure of memory‑resident secrets rather than a full sandbox escape.

Generated by OpenCVE AI on September 10, 2026 at 16:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 153.0.8010.36 or later
  • Ensure that the operating system and Chrome receive automatic updates on the device
  • Avoid visiting untrusted websites that could deliver malicious HTML content

Generated by OpenCVE AI on September 10, 2026 at 16:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome WebView Enables Remote Information Disclosure

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google
Google android
Google chrome
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N'}


Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Out of bounds read in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T15:31:00.744Z

Reserved: 2026-09-08T22:43:48.083Z

Link: CVE-2026-87640

cve-icon Vulnrichment

Updated: 2026-09-10T15:30:40.643Z

cve-icon NVD

Status : Modified

Published: 2026-09-09T01:17:22.413

Modified: 2026-09-10T16:18:06.707

Link: CVE-2026-87640

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T01:00:08Z

Weaknesses