CVE-2026-91737
8.8Google · Chrome
A use after free vulnerability in the PDF component of Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.
Executive summary
A critical use after free vulnerability in Google Chrome allows remote code execution, posing a significant risk to user systems and data integrity.
Vulnerability
This vulnerability is a use after free (CWE-416) flaw located within the PDF rendering engine. An unauthenticated remote attacker can trigger this condition by enticing a user to navigate to a specifically crafted HTML page.
Business impact
The ability for an attacker to achieve remote code execution provides a pathway for full system compromise, data exfiltration, or the installation of persistent malware. With a CVSS score of 8.8, this high-severity vulnerability warrants immediate attention to prevent potential data breaches and unauthorized access to corporate resources.
Remediation
Immediate Action: Update all Google Chrome installations to version 153.0.8010.47 or later immediately.
Proactive Monitoring: Monitor endpoint security logs for unusual browser activity or unexpected child process spawning related to the Chrome rendering engine.
Compensating Controls: Deploy browser isolation technologies or configure endpoint protection platforms to restrict the execution of untrusted scripts and PDF content.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for remote code execution, this vulnerability represents a high risk to all environments utilizing Google Chrome. Administrators should prioritize the deployment of the 153.0.8010.47 security update across all managed workstations to eliminate the attack vector. Failure to patch promptly increases the risk of successful exploitation should a weaponized exploit become available in the future.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written
- Published in the daily brief high section