Executive brief
Google Chrome contains a use-after-free vulnerability in its WebPackaging component that allows remote attackers to execute arbitrary code outside the browser sandbox by opening a malicious HTML page. This vulnerability could enable attackers to bypass Chrome's security protections and gain unauthorized access to sensitive data or compromise the entire system.
Technical details
A use-after-free vulnerability exists in the WebPackaging component of Google Chrome versions prior to 153.0.8010.36. The vulnerability occurs when memory is accessed after it has been freed, allowing an attacker to potentially execute arbitrary code outside the sandbox. The attack requires a user to open a crafted HTML page; no authentication is required. An attacker can exploit this to achieve remote code execution and fully compromise the affected system.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released