Executive brief
Google Chrome contains a use-after-free vulnerability in the Views component that allows a local attacker to execute arbitrary code outside the browser sandbox by interacting with the user interface. A successful exploit could allow an attacker on the same system to bypass Chrome's security isolation and gain full system access, potentially compromising user data, installing malware, or taking complete control of the affected computer.
Technical details
This is a use-after-free vulnerability in Chrome's Views UI framework that occurs when a memory object is accessed after it has been freed. The vulnerability can be triggered through user interface interaction and requires local access to the system. The attack bypasses Chrome's sandbox security boundary, allowing arbitrary code execution with the privileges of the process. The vulnerability affects Chrome versions prior to 153.0.8010.36 and has been patched in that release. The Chromium security team rated this as High severity.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36