Executive brief
Google Chrome is a web browser used by billions of people worldwide. A use-after-free vulnerability in the printing module allows a remote attacker to escape the browser's security sandbox and potentially execute arbitrary code on a victim's computer if they visit a specially crafted webpage. This could lead to full system compromise, malware installation, or theft of sensitive user data.
Technical details
A use-after-free vulnerability exists in Google Chrome's Printing component, affecting versions prior to 153.0.8010.36. The vulnerability requires that an attacker has already compromised the renderer process; from this position, a crafted HTML page can trigger the use-after-free condition and break out of the sandbox to achieve arbitrary code execution outside the sandbox. The attack vector is network-based via a malicious webpage. The vulnerability was patched in Chrome 153.0.8010.36 released on September 9, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed: Public disclosure via Chrome security page and NVD
- 2026-09-09: patched: Fix released in Chrome 153.0.8010.36 for Windows, Mac, and Linux