Impact
Code injection was discovered in the XML handling of Google Chrome prior to version 153.0.8010.47. The flaw allows an attacker to craft an HTML page that, when rendered by Chrome, injects arbitrary XML code and bypasses the browser’s web‑origin policy. This can enable a malicious page to read or manipulate data from other origins, effectively violating same‑origin restrictions. The vulnerability is classified as a low‑severity issue (CVSS score 4.3) by the Chrome security team.
Affected Systems
The affected product is Google Chrome, any installation earlier than version 153.0.8010.47. This includes all desktop builds of the Chrome stable channel that have not yet applied the September 2026 security update. No other browsers or Chrome enterprise components are listed as affected.
Risk and Exploitability
The Exploit Prediction Scoring System indicates an exploitation probability of less than 1 %. The issue is not included in CISA’s KEV catalog, reinforcing its low likelihood of being actively exploited. The exploitation method requires an attacker to deliver a specially crafted HTML page to a user’s browser, so user interaction is a prerequisite. Because the issue is limited to user – side code execution and does not provide direct remote code execution on the host, the overall risk to confidentiality, integrity, or availability remains modest, though it can compromise the isolation between web sites.
OpenCVE Enrichment