CVE-2026-91721

8.8

Google · Chrome

A use after free vulnerability in Google Chrome Internals allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.

Executive summary

A critical use after free vulnerability in Google Chrome enables remote code execution outside the browser sandbox, posing a severe threat to system integrity.

Vulnerability

The vulnerability is a use after free flaw (CWE-416) within the Internals component of Google Chrome. It can be triggered by an unauthenticated remote attacker who lures a user into visiting a specially crafted HTML page.

Business impact

The ability to execute arbitrary code outside the browser sandbox represents a significant security breach. Successful exploitation could lead to full system compromise, unauthorized data access, and the potential installation of persistent malware, justifying the high CVSS score of 8.8.

Remediation

Immediate Action: Update all Google Chrome instances to version 153.0.8010.47 or later immediately to incorporate the necessary memory management fixes.

Proactive Monitoring: Monitor endpoint logs for unusual child process spawns originating from the browser or unexpected network connections following web browsing activity.

Compensating Controls: While browser updates are the primary defense, deploying endpoint detection and response (EDR) solutions can help identify and block malicious code execution attempts originating from browser processes.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for remote code execution and the critical nature of browser-based vulnerabilities, organizations must prioritize the deployment of the 153.0.8010.47 update across all environments. Users and administrators should ensure that automatic updates are enabled and verify that the browser version reflects the patch level to mitigate this risk effectively.

More Google CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources