Executive brief
Google Chrome contains a use-after-free vulnerability in its WebAppInstalls component that allows attackers to execute arbitrary code outside the browser's sandbox. An attacker can exploit this via a crafted HTML page served over the network, potentially giving them full system access and the ability to steal data or install malware on a user's computer.
Technical details
A use-after-free vulnerability exists in the WebAppInstalls component of Google Chrome versions prior to 153.0.8010.47. The vulnerability is triggered when a remote attacker delivers a specially crafted HTML page to a victim, allowing memory that has been freed to be accessed and modified. This memory corruption can be leveraged to escape Chrome's sandbox protections and achieve arbitrary code execution with the privileges of the user running the browser. The vulnerability is classified as High severity by the Chromium security team and has a CVSS score of 9.6. A fix is available in Chrome version 153.0.8010.47 and later.
Affected products
- Google Chrome prior to 153.0.8010.47
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: fix available in Chrome 153.0.8010.47