Description
Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

A buffer overflow arises during GPU operations in Google Chrome for Android versions earlier than 153.0.8010.36. The integer overflow can be triggered by a specially crafted HTML page that a remote attacker can supply, potentially allowing execution of arbitrary code outside the browser sandbox. The flaw falls under CWE-190, reflecting an arithmetic overflow vulnerability. The threat is that a malicious webpage could exploit this defect to escape the browser process and gain full control of the device.

Affected Systems

The vulnerability affects Google Chrome on Android devices running any version before 153.0.8010.36. Any user who visits a malicious webpage in an affected version is at risk. There is currently no device‑specific restriction; all impacted Android installations using the affected Chrome build are vulnerable.

Risk and Exploitability

The issue has a CVSS score of 9.6, indicating a high severity. The exploit requires only a crafted HTML page accessed through a remote attacker, implying that the attack vector is a web‑based input. The EPSS score is < 1% and the vulnerability is not listed in CISA KEV, but the high CVSS score and its ability to escape the sandbox make exploitation potentially damaging. Users should expect that an attacker could compromise device security if the flaw is leveraged.

Generated by OpenCVE AI on September 9, 2026 at 17:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome on Android to version 153.0.8010.36 or later
  • Ensure that the device automatically receives Chrome updates and install any available patches promptly
  • If an update cannot be applied immediately, disable GPU acceleration or restrict browsing of untrusted content to reduce the attack surface

Generated by OpenCVE AI on September 9, 2026 at 17:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Android Chrome GPU Integer Overflow Allowing Remote Code Execution Outside Sandbox

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google
Google android
Google chrome

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Android Chrome GPU Integer Overflow Allowing Remote Code Execution Outside Sandbox

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Integer overflow in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-190
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:55:45.896Z

Reserved: 2026-09-08T22:43:51.699Z

Link: CVE-2026-87643

cve-icon Vulnrichment

Updated: 2026-09-09T13:29:56.958Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:22.740

Modified: 2026-09-10T04:18:31.053

Link: CVE-2026-87643

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T10:30:04Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound