Executive brief
Google Chrome is a widely-used web browser that processes web content and runs applications. A use-after-free vulnerability in the Input component allows attackers to execute arbitrary code within the browser's sandbox via a malicious HTML page, potentially leading to code execution that could compromise user data or browser functionality.
Technical details
This vulnerability is a use-after-free memory safety issue in Chrome's Input component. It allows a remote attacker to execute arbitrary code within the browser sandbox by crafting a malicious HTML page. The attack requires no authentication and can be triggered simply by visiting or interacting with a compromised webpage. The vulnerability was patched in Chrome version 153.0.8010.36 and later. Although the vulnerability permits sandbox escape techniques, the initial exploit is contained within the sandbox; full system compromise would require additional privilege escalation.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36