Description
Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution outside sandbox
Action: Immediate Patch
AI Analysis

Impact

A buffer overflow in Chrome’s ANGLE component on Windows, affecting all releases prior to 153.0.8010.36, permits a remote attacker to execute arbitrary code beyond the browser sandbox. The flaw is a classic stack or heap overflow (CWE-122) that can be triggered by a crafted HTML page. The description notes that the impact is high in Chromium’s severity grading, indicating significant risk to confidentiality, integrity, and availability of the system.

Affected Systems

The affected product is Google Chrome for Windows, specifically any installation running a version earlier than 153.0.8010.36. No other vendors or versions are listed.

Risk and Exploitability

The vulnerability is classified as high severity, with a CVSS score of 9.6, but the EPSS score is < 1% and it is not currently listed in CISA’s KEV catalog, suggesting a lower publicly verified exploitation probability. The likely attack vector is remote, via a maliciously constructed HTML page delivered over the network. Based on the description, it is inferred that an attacker can trigger the overflow by directing a user to the crafted page, leading to code execution outside the browser’s sandbox. Without known active exploits, the risk remains theoretical, yet the high Chromium severity indicates strong potential for exploitation if an attacker discovers or develops a payload.

Generated by OpenCVE AI on September 9, 2026 at 19:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 153.0.8010.36 or later. This release includes the ANGLE patch that eliminates the buffer overflow.
  • Ensure automatic updates are enabled so future security fixes are applied without manual intervention.
  • Monitor user activity and network traffic for abnormal behavior that could indicate an attempt to exploit the browser, and apply network filtering rules to block malicious content if such activity is detected.

Generated by OpenCVE AI on September 9, 2026 at 19:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Buffer Overflow in Chrome ANGLE on Windows

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome
Microsoft
Microsoft windows

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Buffer Overflow in Chrome ANGLE on Windows

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Buffer overflow in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-122
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:55:55.454Z

Reserved: 2026-09-08T22:44:20.222Z

Link: CVE-2026-87654

cve-icon Vulnrichment

Updated: 2026-09-09T13:30:41.655Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:23.933

Modified: 2026-09-10T04:18:31.987

Link: CVE-2026-87654

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T16:00:13Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow