Description
Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Published: 2026-09-29
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Update
AI Analysis

Impact

Improper input validation in the processing of themes allows a remote attacker who has already compromised the renderer process to potentially execute arbitrary code inside the renderer’s sandbox via crafted network traffic. The flaw arises from insufficient sanitization of theme data, enabling code execution with the sandboxed renderer’s privileges. Based on the description, it is inferred that the attacker’s capabilities are limited to the sandbox and the option to escape to the host system is not explicitly documented.

Affected Systems

Google Chrome desktop releases before version 154.0.8037.57 are affected, as indicated in the CVE data.

Risk and Exploitability

The CVSS score of 8.3 categorises this vulnerability as high severity. EPSS data is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a remote attacker to have already gained control of the renderer process, which typically involves a sophisticated threat actor. Based on the description, it is inferred that the attacker can run code inside the sandbox but there is no evidence of a full system compromise.

Generated by OpenCVE AI on September 30, 2026 at 00:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Chrome to version 154.0.8037.57 or newer.
  • Disable or restrict third‑party theme installation through Chrome Enterprise policy or group policy.
  • Ensure Chrome’s sandboxing feature remains enabled for all renderer processes.
  • Apply strict input validation for theme data to prevent malicious content, addressing the CWE‑20 vulnerability.

Generated by OpenCVE AI on September 30, 2026 at 00:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6513-1 chromium security update
History

Wed, 30 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Improper Theme Input Validation in Chrome

Tue, 29 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-30T03:56:34.421Z

Reserved: 2026-09-22T05:06:56.896Z

Link: CVE-2026-95276

cve-icon Vulnrichment

Updated: 2026-09-29T18:17:35.230Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-29T18:17:18.843

Modified: 2026-09-30T04:18:38.080

Link: CVE-2026-95276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T00:30:17Z

Weaknesses
  • CWE-20

    Improper Input Validation