Executive brief
Google Chrome, the widely-used web browser, contains a memory safety vulnerability in its authentication component. An attacker can craft a malicious web page that, when visited, exploits this vulnerability to break out of Chrome's security sandbox and execute arbitrary code with full system privileges. This could lead to complete compromise of a user's device, including theft of sensitive data, installation of malware, or unauthorized access to online accounts.
Technical details
This vulnerability is a use-after-free in the Auth component of Google Chrome versions prior to 153.0.8010.47. The root cause involves memory corruption where the Auth subsystem accesses memory that has already been freed, leading to undefined behavior. An attacker can trigger the vulnerability by delivering a crafted HTML page to a target user; no prior authentication or elevated privileges are required. Successful exploitation allows the attacker to execute arbitrary code outside the Chrome sandbox (in the browser process itself or host system), completely bypassing Chrome's multi-process security architecture. The vulnerability has been addressed in Chrome 153.0.8010.47 and later.
Affected products
- Google Chrome prior to 153.0.8010.47
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fixed in Chrome 153.0.8010.47