CVE-2026-91716

Google · Chrome

A use after free vulnerability in the Google Chrome Auth component allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.

Executive summary

A critical use after free vulnerability in Google Chrome allows unauthenticated remote attackers to achieve arbitrary code execution via malicious web content.

Vulnerability

This is a use after free vulnerability (CWE-416) within the Auth component of Google Chrome. An unauthenticated remote attacker can trigger this flaw by enticing a user to visit a crafted HTML page, leading to code execution outside the browser sandbox.

Business impact

The ability to execute arbitrary code outside the browser sandbox poses a severe risk to organizational security, potentially allowing an attacker to gain full control over the host system. Given the CVSS score of 9.6, this vulnerability represents a critical threat to data confidentiality, system integrity, and availability. Successful exploitation could lead to widespread malware deployment, credential theft, or lateral movement within the corporate network.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.47 or later immediately to apply the vendor-supplied security patch.

Proactive Monitoring: Monitor endpoint security logs for unusual process execution or unauthorized network connections originating from the browser process.

Compensating Controls: Ensure that modern browser sandbox features are enabled and utilize endpoint detection and response (EDR) solutions to identify and block suspicious exploitation patterns.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Due to the critical severity and the potential for complete system compromise via sandbox escape, organizations must prioritize the deployment of the patch for Google Chrome. IT teams should ensure that auto-update mechanisms are functioning correctly or push the update via centralized management tools to mitigate the risk of remote code execution.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.6 (3.1)
  4. Analyst report written

Sources