CVE-2026-91710
Google · Chrome
A use after free vulnerability in Google Chrome WebAppInstalls allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
Executive summary
A critical use after free vulnerability in Google Chrome allows unauthenticated remote attackers to achieve arbitrary code execution through crafted web content.
Vulnerability
This is a use after free vulnerability (CWE-416) within the WebAppInstalls component. An unauthenticated remote attacker can trigger this flaw by enticing a user to visit a malicious HTML page, leading to sandbox escape and arbitrary code execution.
Business impact
The ability for an attacker to execute arbitrary code outside the browser sandbox poses a severe risk to organizational security. Successful exploitation could lead to full system compromise, unauthorized data exfiltration, or the installation of persistent malware on user workstations. Given the CVSS score of 9.6, this vulnerability is classified as critical due to the potential for total impact on confidentiality, integrity, and availability.
Remediation
Immediate Action: Update all Google Chrome installations to version 153.0.8010.47 or later immediately to incorporate the necessary memory management fixes.
Proactive Monitoring: Monitor endpoint detection and response logs for anomalous process spawning or suspicious network traffic originating from the browser process.
Compensating Controls: While no direct virtual patch exists for use after free flaws, utilizing browser-based security policies and disabling unnecessary web app features may reduce the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The severity of this vulnerability necessitates immediate attention from IT and security teams. Because this flaw allows for code execution outside the security boundary of the browser, administrators must prioritize the deployment of the latest Chrome update across all managed devices to mitigate the risk of remote compromise.
More Google CVEs all →
History
CVE Brief tracked this CVE 3 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.6 (3.1)
- Analyst report written