Executive brief
Google Chrome's DevTools component contains a use-after-free vulnerability that allows a local attacker to execute arbitrary code outside the browser sandbox. This means an attacker with local access to a computer can potentially run malicious software with elevated privileges, bypassing Chrome's security isolation mechanisms that normally restrict what web code can do.
Technical details
A use-after-free vulnerability exists in the DevTools component of Google Chrome prior to version 153.0.8010.36. The vulnerability allows a local attacker to execute arbitrary code outside the sandbox via interaction with a local program. The attack requires local access to the affected system and can result in arbitrary code execution with the privileges of the Chrome process. The vulnerability has been patched in Chrome 153.0.8010.36 and later versions.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released