Junglewise Threat Intelligence

CVE-2026-91718: Google Chrome use-after-free in Core

CVE-2026-91718 · Severity: critical · CVSS 9.6 · Published 2026-09-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a memory safety vulnerability in its core rendering engine that could allow an attacker to execute malicious code outside the browser's security sandbox. An attacker can trigger this flaw by crafting a malicious webpage; when a user visits the page, the attacker gains the ability to run arbitrary code with full system privileges, bypassing Chrome's security protections.

Technical details

A use-after-free vulnerability exists in Google Chrome's Core component (version prior to 153.0.8010.47). The vulnerability is triggered when a specially crafted HTML page is loaded, causing the browser to reference memory that has already been freed. This memory safety bug allows a remote attacker to achieve arbitrary code execution outside the sandbox boundary, meaning the attacker can interact directly with the operating system. The flaw requires no user authentication and can be exploited over the network by serving a malicious webpage. Google released version 153.0.8010.47 to fix this issue.

Affected products

  • Google Chrome prior to 153.0.8010.47

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in Chrome 153.0.8010.47

References

Related threats