Executive brief
Google Chrome contains a flaw in how it resolves references within its Storage component on Windows. An attacker who gains control of Chrome's renderer process (the component that interprets web pages) could exploit this to execute arbitrary code outside of Chrome's security sandbox, potentially gaining full system access. This could allow attackers to bypass Chrome's built-in protections and compromise a user's computer.
Technical details
This vulnerability is an incorrect reference resolution flaw in Chrome's Storage component affecting Windows versions prior to 153.0.8010.36. The vulnerability requires an attacker to first compromise the Chrome renderer process—the sandboxed component responsible for parsing and executing web content. Once the renderer is compromised, an attacker can craft a malicious HTML page that exploits the incorrect reference resolution to escape the sandbox and execute arbitrary code with the privileges of the browser process outside protected memory boundaries. The vulnerability was patched in Chrome 153.0.8010.36 released on September 8, 2026. Google assigned this a "Low" Chromium security severity rating, but the NVD rated it as "High" with a CVSS score of 8.3, reflecting the serious impact of sandbox escape.
Affected products
- Google Chrome prior to 153.0.8010.36 on Windows
Timeline
- 2026-09-08: disclosed: Chrome 153.0.8010.36 released with fix
- 2026-09-08: patched