CVE-2026-91736
8.8Google · Chrome
A use after free vulnerability in the Google Chrome DOM allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.
Executive summary
A critical use after free vulnerability in Google Chrome allows remote code execution and requires immediate patching to prevent arbitrary code execution.
Vulnerability
This is a use after free vulnerability (CWE-416) within the DOM implementation of Google Chrome. A remote, unauthenticated attacker can exploit this flaw by enticing a user to visit a specially crafted HTML page, leading to arbitrary code execution within the browser sandbox.
Business impact
The ability for an unauthenticated remote attacker to execute arbitrary code represents a significant threat to endpoint security and data confidentiality. With a CVSS score of 8.8, this high-severity flaw could lead to the complete compromise of the browser environment, potential malware installation, or unauthorized access to sensitive user data stored within the browser session.
Remediation
Immediate Action: Update all Google Chrome installations to version 153.0.8010.47 or later immediately to incorporate the necessary security fixes.
Proactive Monitoring: Monitor endpoint logs for suspicious browser crashes or unexpected behavior that may indicate an attempt to trigger a memory corruption vulnerability.
Compensating Controls: Ensure that browser-based security features, such as site isolation and sandbox protections, are fully enabled and not bypassed by group policy or configuration changes.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for remote code execution and the ubiquity of Google Chrome in enterprise environments, this vulnerability poses a substantial risk. IT administrators should prioritize the deployment of the 153.0.8010.47 update across all managed workstations to ensure effective mitigation. Failure to patch may expose users to browser-based attacks that bypass standard security controls.
More Google CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section