Executive brief
Google Chrome contains a use-after-free vulnerability in its Web Authentication component that allows attackers to execute arbitrary code outside the browser sandbox. An attacker can exploit this by hosting a specially crafted HTML page and tricking a user into visiting it, potentially leading to complete system compromise since the malicious code runs with the privileges of the browser process.
Technical details
A use-after-free vulnerability exists in the Web Authentication component of Google Chrome versions prior to 153.0.8010.36. This vulnerability allows memory to be accessed after it has been freed, leading to memory corruption. An attacker can craft a malicious HTML page that, when visited by a user, triggers the use-after-free condition and achieves arbitrary code execution outside the sandbox boundary. This requires user interaction (visiting a malicious website) but no authentication. The vulnerability is fixed in Chrome 153.0.8010.36 and later releases.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36