CVE-2026-91711

8.8

Google · Chrome

An out of bounds write vulnerability in the Google Chrome ServiceWorker component allows a remote attacker to execute arbitrary code within the browser sandbox via a crafted HTML page.

Executive summary

Google Chrome versions prior to 153.0.8010.47 are vulnerable to a remote code execution flaw that allows attackers to compromise the browser sandbox through malicious web content.

Vulnerability

This is an out of bounds write vulnerability (CWE-787) residing in the ServiceWorker component. The flaw allows an unauthenticated remote attacker to execute arbitrary code within the browser sandbox by enticing a user to navigate to a specifically crafted HTML page.

Business impact

Successful exploitation of this vulnerability poses a severe risk to organizational security, as it enables remote code execution on end-user systems. With a CVSS score of 8.8, this high-severity flaw could lead to full system compromise, sensitive data exfiltration, or the deployment of further malware within the corporate network.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.47 or later immediately to incorporate the vendor-supplied fix.

Proactive Monitoring: Monitor endpoint security logs for unexpected process spawns originating from the Chrome browser or unusual network activity related to the ServiceWorker process.

Compensating Controls: Ensure that browser-based security policies are enforced and utilize endpoint protection platforms capable of identifying and blocking malicious script execution.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the capability for remote code execution and the ubiquity of Google Chrome in enterprise environments, this vulnerability represents a significant security risk. Administrators should prioritize the deployment of the 153.0.8010.47 update across all workstations to remediate the flaw and maintain the integrity of the browser sandbox.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written
  5. Published in the daily brief high section

Sources