Executive brief
Google Chrome contains a use-after-free vulnerability in its internal memory management that could allow attackers to escape the browser's security sandbox and execute arbitrary code on a user's computer. An attacker can exploit this by hosting a malicious HTML page and tricking a user into visiting it, potentially leading to full system compromise.
Technical details
A use-after-free vulnerability exists in Chrome's Internals component, where memory is accessed after being freed during execution. The vulnerability can be triggered via a crafted HTML page delivered over the network, requiring only that a user visit the malicious page—no authentication or user interaction beyond navigation is needed. Successful exploitation allows an attacker to break out of Chrome's sandbox and execute arbitrary code with the privileges of the user running the browser, leading to complete system compromise. The vulnerability is patched in Chrome version 153.0.8010.47 and later.
Affected products
- Google Chrome prior to 153.0.8010.47
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fixed in Chrome 153.0.8010.47