Description
Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program. (Chromium security severity: Medium)
Published: 2026-09-17
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Disclosure
Action: Patch Now
AI Analysis

Impact

An out‑of‑bounds read occurs in Chrome’s DataTransfer component, allowing a local attacker to read memory outside the sandboxed environment. The flaw is classified as CWE‑125 and can leak sensitive information that resides in protected memory areas. The vulnerability is limited to local code execution contexts and does not provide a path to arbitrary code execution or system compromise.

Affected Systems

Google Chrome desktop builds prior to version 153.0.8010.52 are affected. The issue was identified in the stable channel and addressed in the 153.0.8010.52 release. Users operating earlier Chrome versions are at risk if they run untrusted local programs.

Risk and Exploitability

The CVSS score of 6.3 reflects a medium severity condition, while an EPSS score of less than 1% indicates a very low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog, suggesting it has not been actively exploited publicly. Exploitation requires a local attacker to successfully persuade a user to run a crafted program, so the primary attack vector is local social engineering. Once executed, the vulnerability allows memory disclosure that could expose credentials or other private data.

Generated by OpenCVE AI on September 19, 2026 at 18:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Chrome to version 153.0.8010.52 or later
  • Implement application restrictions or whitelist to block execution of untrusted local programs that could exploit DataTransfer.
  • Educate users on social engineering tactics and avoid running unknown local applications.

Generated by OpenCVE AI on September 19, 2026 at 18:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6508-1 chromium security update
History

Mon, 21 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Sat, 19 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome DataTransfer Allows Local Attacker Memory Read

Sat, 19 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome DataTransfer Allows Local Attacker Memory Read

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Description Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program. (Chromium security severity: Medium)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-18T13:31:04.813Z

Reserved: 2026-09-17T19:34:41.270Z

Link: CVE-2026-93376

cve-icon Vulnrichment

Updated: 2026-09-18T13:11:43.815Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T21:17:54.890

Modified: 2026-09-21T12:54:26.620

Link: CVE-2026-93376

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:45:14Z

Weaknesses