Executive brief
Google Chrome is a web browser used by hundreds of millions of people worldwide to access websites and web applications. A vulnerability in the Extensions component allows a remote attacker to execute malicious code outside Chrome's security sandbox via a specially crafted webpage, potentially giving attackers full control of an affected user's computer and access to all stored passwords, files, and personal data.
Technical details
This is a use-after-free vulnerability in the Extensions component of Google Chrome on macOS. A remote attacker can exploit this flaw by crafting a malicious HTML page that, when visited by a user, triggers the use-after-free condition and achieves arbitrary code execution outside the Chrome sandbox. The vulnerability affects Chrome versions prior to 153.0.8010.36/37 and was patched in that release. Exploitation does not require prior authentication or user interaction beyond visiting the malicious page.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released