Junglewise Threat Intelligence

CVE-2026-91727: Google Chrome incorrect reference resolution in Extensions on Mac

CVE-2026-91727 · Severity: high · CVSS 8.1 · Published 2026-09-15

Executive brief

Google Chrome on macOS contains a vulnerability in how it resolves references within browser extensions. An attacker who has already compromised the browser's renderer process could exploit this flaw to execute arbitrary code outside the browser's sandbox and run it as a local program, potentially gaining full system access.

Technical details

This vulnerability exists in the extension reference resolution mechanism within Google Chrome on macOS. The flaw allows incorrect reference handling that can be exploited by a local attacker who has achieved code execution within the renderer process. By leveraging this vulnerability, an attacker can escape the browser sandbox and execute arbitrary code as a local program on the system. The vulnerability affects Chrome versions prior to 153.0.8010.47 on macOS. Google has rated this with Chromium high severity and assigned a CVSS score of 8.1. A patch is available in Chrome 153.0.8010.47 and later.

Affected products

  • Google Chrome prior to 153.0.8010.47 on macOS

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: patched in Chrome 153.0.8010.47

References

Related threats