Description
Race condition in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Update Browser
AI Analysis

Impact

A race condition in Google Chrome before version 153.0.8010.36 allows a remote attacker to craft a malicious HTML page that can bypass system access restrictions. The vulnerability is classified as a medium‑severity Chromium bug, and the flaw can lead to unauthorized privilege escalation on the victim’s machine.

Affected Systems

All users running Google Chrome, any version older than 153.0.8010.36, on any supported operating system, are impacted.

Risk and Exploitability

Based on the description, the attacker must first deliver a malicious HTML page to the victim’s Chrome browser. The low EPSS score of < 1% and lack of a CISA KEV listing imply that this vulnerability is rarely exploited in the wild. The CVSS score of 5.3 indicates medium severity, and combined with the low exploitation probability, the overall risk is moderate. Nevertheless, an active exploitation would let the attacker bypass normal system access restrictions and achieve privilege escalation on the affected machine.

Generated by OpenCVE AI on September 10, 2026 at 18:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 153.0.8010.36 or later
  • Enable Chrome’s auto‑update feature to receive security patches automatically
  • If upgrading is not possible, restrict Chrome usage to approved sites or disable web content that can trigger the race condition

Generated by OpenCVE AI on September 10, 2026 at 18:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Title Race Condition Allows Remote Privilege Escalation via Crafted HTML in Chrome

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Thu, 10 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Wed, 09 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Title Race Condition Allows Remote Privilege Escalation via Crafted HTML in Chrome

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Race condition in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-362
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T14:06:02.106Z

Reserved: 2026-09-08T22:43:49.106Z

Link: CVE-2026-87641

cve-icon Vulnrichment

Updated: 2026-09-10T14:05:31.555Z

cve-icon NVD

Status : Modified

Published: 2026-09-09T01:17:22.520

Modified: 2026-09-10T15:17:53.507

Link: CVE-2026-87641

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T01:30:13Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')