Description
Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-15
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Chrome’s WebUI authorization flaw allows a remote attacker who has already compromised the renderer process to craft a malicious HTML page that can execute code outside the sandbox. The weakness is an authorization bypass (CWE‑863) combined with improper authorization (CWE‑266), meaning that privileged actions are performed based on user‑controlled input that should not be trusted. This vulnerability carries a CVSS score of 8.3, indicating high severity and the possibility of full system compromise if successful.

Affected Systems

Google Chrome desktop versions prior to 153.0.8010.47 contain the vulnerable WebUI implementation. All builds of the stable channel before this revision are affected.

Risk and Exploitability

The EPSS score is below 1 %, suggesting a low exploitation probability, and the vulnerability is not listed in CISA KEV. In practice, the attacker would need to serve malicious content that gains control of the renderer process and then exploit the combined authorization weaknesses in the WebUI to escape the sandbox. If successful, the attacker could run code with the local user’s privileges or potentially higher, depending on the sandbox configuration. The attack vector requires an initial compromise of the renderer process; the flaw alone does not grant remote code execution from outside the browser.

Generated by OpenCVE AI on September 22, 2026 at 13:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.47 or later, which contains the WebUI authorization fix.
  • Configure Chrome administrative policies to enforce strict sandboxing for renderer processes and restrict WebUI access; use policy settings to disable or isolate extensions that interact with WebUI when the issue is not yet fixed.
  • Enable automatic updates and set the browser to the stable or rapid channel to ensure the patch is applied promptly.

Generated by OpenCVE AI on September 22, 2026 at 13:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Tue, 22 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Incorrect authorization in WebUI
Weaknesses CWE-266
References
Metrics threat_severity

None

threat_severity

Important


Fri, 18 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Title Chrome WebUI Authorization Flaw Enabling Remote Code Execution

Thu, 17 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 16 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Title Chrome WebUI Authorization Flaw Enabling Remote Code Execution

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-17T03:56:16.584Z

Reserved: 2026-09-14T22:52:31.449Z

Link: CVE-2026-91735

cve-icon Vulnrichment

Updated: 2026-09-15T23:46:00.819Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T21:16:47.020

Modified: 2026-09-17T16:03:04.173

Link: CVE-2026-91735

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-15T20:41:31Z

Links: CVE-2026-91735 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T14:00:19Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-863

    Incorrect Authorization