CVE-2026-91745
8.8Google · Chrome
A use after free vulnerability in the V8 engine of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
Executive summary
A critical use after free vulnerability in Google Chrome versions prior to 153.0.8010.47 poses a significant risk of arbitrary code execution for users navigating to malicious websites.
Vulnerability
This is a use after free flaw (CWE-416) within the V8 JavaScript engine. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to visit a specially crafted HTML page, potentially leading to arbitrary code execution within the browser sandbox.
Business impact
The exploitation of this vulnerability allows for remote code execution, which could lead to a complete compromise of the browser session. With a CVSS score of 8.8, this high-severity flaw threatens data confidentiality and integrity by enabling attackers to bypass security controls. Organizations face risks of sensitive data exfiltration or the installation of malicious software on user workstations.
Remediation
Immediate Action: Update all instances of Google Chrome to version 153.0.8010.47 or later immediately to incorporate the necessary security patches.
Proactive Monitoring: Monitor endpoint logs for unusual browser activity or unexpected crashes that may indicate exploitation attempts.
Compensating Controls: Ensure that endpoint protection software is active and updated, as it may provide behavioral detection for malicious browser-based payloads.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for remote code execution, this vulnerability represents a significant risk to organizational security. Administrators should prioritize the deployment of the Chrome update across all managed devices to ensure that the V8 engine is secured against this memory corruption flaw.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written
- Published in the daily brief high section