CVE-2026-91736

8.8

Google · Chrome

A use after free vulnerability in the Google Chrome DOM allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.

Executive summary

A critical use after free vulnerability in Google Chrome allows remote code execution and requires immediate patching to prevent arbitrary code execution.

Vulnerability

This is a use after free vulnerability (CWE-416) within the DOM implementation of Google Chrome. A remote, unauthenticated attacker can exploit this flaw by enticing a user to visit a specially crafted HTML page, leading to arbitrary code execution within the browser sandbox.

Business impact

The ability for an unauthenticated remote attacker to execute arbitrary code represents a significant threat to endpoint security and data confidentiality. With a CVSS score of 8.8, this high-severity flaw could lead to the complete compromise of the browser environment, potential malware installation, or unauthorized access to sensitive user data stored within the browser session.

Remediation

Immediate Action: Update all Google Chrome installations to version 153.0.8010.47 or later immediately to incorporate the necessary security fixes.

Proactive Monitoring: Monitor endpoint logs for suspicious browser crashes or unexpected behavior that may indicate an attempt to trigger a memory corruption vulnerability.

Compensating Controls: Ensure that browser-based security features, such as site isolation and sandbox protections, are fully enabled and not bypassed by group policy or configuration changes.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for remote code execution and the ubiquity of Google Chrome in enterprise environments, this vulnerability poses a substantial risk. IT administrators should prioritize the deployment of the 153.0.8010.47 update across all managed workstations to ensure effective mitigation. Failure to patch may expose users to browser-based attacks that bypass standard security controls.

More Google CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources