Executive brief
Google Chrome contains a use-after-free vulnerability in its Views component that allows a local attacker to execute arbitrary code outside the browser's sandbox. An attacker with local access to a system running Chrome can exploit this to bypass browser security protections and run malicious code with system privileges, potentially compromising sensitive data or taking full control of the machine.
Technical details
This is a use-after-free vulnerability in the Views UI framework component of Google Chrome prior to version 153.0.8010.36. The vulnerability allows a local attacker to exploit memory management issues by accessing freed memory, leading to code execution. The attack requires local access to the system running Chrome and does not require user interaction. Successful exploitation grants the attacker the ability to execute arbitrary code outside the browser sandbox, effectively breaking Chrome's security isolation and allowing system-level compromise. The vulnerability has been fixed in Chrome 153.0.8010.36 and subsequent releases.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released