Junglewise Threat Intelligence

CVE-2026-91724: Google Chrome use-after-free in Input component

CVE-2026-91724 · Severity: high · CVSS 8.3 · Published 2026-09-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a memory safety vulnerability in its input handling that affects versions prior to 153.0.8010.47. An attacker who compromises the browser's rendering engine could exploit this flaw to execute malicious code outside of Chrome's security sandbox, potentially gaining full control over the affected system. This could allow unauthorized access to sensitive data, installation of malware, or complete system compromise.

Technical details

A use-after-free vulnerability exists in the Input component of Google Chrome prior to version 153.0.8010.47. The flaw allows a remote attacker who has already compromised the renderer process to bypass the sandbox by crafting a malicious HTML page that triggers the vulnerability. The attack requires prior compromise of the renderer (e.g., through a separate RCE or network-level attack) and user interaction to visit a crafted webpage. Successful exploitation results in arbitrary code execution outside the sandbox with the privileges of the Chrome process. The vulnerability has been assigned high severity by Chromium and has a CVSS score of 8.3; a patch is available in Chrome 153.0.8010.47 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.47

Timeline

  • 2026-09-15: disclosed

References

Related threats