Executive brief
Google Chrome is a web browser used by billions of people worldwide to access web content and online services. A use-after-free vulnerability in the Platform component could allow an attacker to execute malicious code within Chrome's sandbox by tricking a user into visiting a specially crafted website, potentially compromising user data, sessions, and system security.
Technical details
This is a use-after-free vulnerability in the Platform component of Google Chrome prior to version 153.0.8010.36. The vulnerability allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. Use-after-free bugs occur when memory is freed but continues to be referenced, which can be exploited to achieve code execution. The attack vector is network-based and requires user interaction (visiting a malicious web page). The vulnerability was patched in Chrome 153.0.8010.36 and later versions.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released