Junglewise Threat Intelligence

CVE-2026-91722: Google Chrome use-after-free in Input component

CVE-2026-91722 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a use-after-free vulnerability in its input handling that allows attackers to execute arbitrary code outside the browser's security sandbox. An attacker could exploit this by tricking a user into visiting a malicious webpage, potentially compromising the entire system with the same privileges as the browser process.

Technical details

The vulnerability is a use-after-free condition in Chrome's Input component, allowing remote code execution outside the sandbox. An attacker can craft a malicious HTML page that triggers the vulnerable code path when visited by a user. No user authentication is required; the attack is delivered via network through a web page. Exploitation results in arbitrary code execution with the privileges of the Chrome process, bypassing the sandbox isolation mechanism. The vulnerability was patched in Chrome 153.0.8010.47 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.47

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in Chrome 153.0.8010.47

References

Related threats