Description
Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized system access
Action: Apply patch
AI Analysis

Impact

A vulnerability in Google Chrome’s Safe Browsing feature allows a remote attacker to craft an HTML page that bypasses system access restrictions. The weakness is an improper state validation that can be triggered by a maliciously constructed page. As a result, an attacker could gain unauthorized access to system resources normally protected by browser isolation policies.

Affected Systems

The flaw impacts all Chrome releases prior to version 153.0.8010.36, affecting users of the Google Chrome browser across all supported platforms.

Risk and Exploitability

Chromium rates the severity of the issue with a CVSS score of 5.4, indicating moderate severity. The EPSS score is less than 1%, indicating a low but nonzero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack requires only a crafted HTML page delivered to a victim’s browser, implying a remote exploitation over the web with modest effort. With a CVSS score of 5.4, the risk is moderate, suggesting that exploitation would be limited to the browser context and may be mitigated by user awareness and timely patching.

Generated by OpenCVE AI on September 10, 2026 at 16:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.36 or newer.
  • If an immediate upgrade is not possible, configure Chrome’s enterprise policies to restrict or disable loading of arbitrary HTML content from untrusted origins, or enforce a strict content security policy.
  • Continuously monitor for signs of unauthorized access and apply network segmentation to limit any potential lateral movement by malicious code.

Generated by OpenCVE AI on September 10, 2026 at 16:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Chrome Safebrowsing State Validation Vulnerability Enables Remote System Access via Crafted HTML

Thu, 10 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Wed, 09 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title Chrome Safebrowsing State Validation Vulnerability Enables Remote System Access via Crafted HTML

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-754
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-14T12:33:51.006Z

Reserved: 2026-09-08T22:44:23.155Z

Link: CVE-2026-87656

cve-icon Vulnrichment

Updated: 2026-09-14T12:33:45.957Z

cve-icon NVD

Status : Modified

Published: 2026-09-09T01:17:24.167

Modified: 2026-09-14T13:18:59.723

Link: CVE-2026-87656

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:15:16Z

Weaknesses
  • CWE-754

    Improper Check for Unusual or Exceptional Conditions