Description
Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

Chrome on Windows before version 153.0.8010.36 contains a use‑after‑free vulnerability in the ANGLE graphics library. This flaw allows a remote attacker who has already compromised the renderer process to craft a malicious HTML page that can execute arbitrary code outside the sandbox. The attack compromises confidentiality, integrity, and availability by enabling code execution under the user’s privileges.

Affected Systems

The affected system is Google Chrome running on Windows machines. Versions earlier than 153.0.8010.36 are impacted; the vulnerability exists in the renderer component when ANGLE is used.

Risk and Exploitability

The CVSS severity is high with a score of 8.3, and the EPSS score is <1%, indicating a very low exploitation probability. The flaw is not listed in the CISA KEV catalog. Attackers must first gain the ability to execute code within the renderer process, which is a privileged but non‑elevated context; from there, they can use the use‑after‑free to run code outside the sandbox. The window of opportunity exists while the vulnerable processor execute path is active and the browser is loading a crafted HTML page.

Generated by OpenCVE AI on September 9, 2026 at 18:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 153.0.8010.36 or later, which includes a fix for the use‑after‑free (CWE‑416) in ANGLE.
  • If an immediate update is not possible, isolate untrusted web content by using site isolation and enforcing strict content‑security‑policy settings to limit renderer privileges.
  • Ensure that the Chrome sandbox is enabled and the renderer process is running in a separate memory space to mitigate the impact if the vulnerability is present.

Generated by OpenCVE AI on September 9, 2026 at 18:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in ANGLE Allows Remote Code Execution Outside Sandbox

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome
Microsoft
Microsoft windows

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in ANGLE Allows Remote Code Execution Outside Sandbox

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:56:09.215Z

Reserved: 2026-09-08T22:44:01.118Z

Link: CVE-2026-87648

cve-icon Vulnrichment

Updated: 2026-09-09T14:12:29.653Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:23.287

Modified: 2026-09-10T04:18:31.550

Link: CVE-2026-87648

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T10:30:04Z

Weaknesses