CVE-2026-91738

Google · Chrome

A vulnerability in the ANGLE graphics engine of Google Chrome allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page.

Executive summary

Google Chrome versions prior to 153.0.8010.47 contain a critical input validation flaw in the ANGLE component that permits remote code execution through malicious web content.

Vulnerability

This vulnerability involves improper input validation within the ANGLE graphics engine, which can be triggered by an unauthenticated attacker via a specially crafted HTML page. Successful exploitation allows the attacker to bypass the browser sandbox, leading to arbitrary code execution on the underlying host system.

Business impact

The ability to execute arbitrary code outside the browser sandbox presents a severe risk to organizational security, as it grants attackers potential control over the victim host. Given the CVSS score of 9.6, this vulnerability poses a critical threat, as it could lead to full system compromise, data exfiltration, or the deployment of persistent malware within the internal network.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.47 or later immediately to incorporate the necessary security patches.

Proactive Monitoring: Security teams should review endpoint detection and response (EDR) logs for anomalous process spawning originating from the Google Chrome browser process.

Compensating Controls: While browser-level patches are the primary defense, ensure that standard security policies, such as the principle of least privilege, are enforced on all workstations to limit the impact of potential sandbox escapes.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the critical severity and the potential for complete system compromise, organizations must treat this update with high urgency. Administrators should prioritize the deployment of Chrome version 153.0.8010.47 across the fleet to neutralize the risk of sandbox escape and remote code execution.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.6 (3.1)
  4. Analyst report written

Sources