Junglewise Threat Intelligence

CVE-2026-91735: Google Chrome incorrect authorization in WebUI

CVE-2026-91735 · Severity: high · CVSS 8.3 · Published 2026-09-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, the widely-used web browser, contains an authorization flaw in its WebUI component that could allow an attacker with access to the renderer process to escape the browser's sandbox and execute arbitrary code on the system. An attacker could exploit this via a crafted HTML page to gain unauthorized access to system resources and potentially compromise the entire device.

Technical details

This vulnerability is an incorrect authorization issue in the WebUI component of Google Chrome. The vulnerability affects versions prior to 153.0.8010.47 and requires an attacker to have already compromised the renderer process, which can be achieved through a crafted HTML page. The core issue is insufficient authorization checks that allow escape from the browser's sandbox and execution of arbitrary code outside normal browser confinement. Chrome versions 153.0.8010.47 and later contain the fix. The attack vector is network-based and requires user interaction to load a malicious HTML page.

Affected products

  • Google Chrome prior to 153.0.8010.47

Timeline

  • 2026-09-15: disclosed: Vulnerability disclosed by Google
  • 2026-09-15: patched: Fix released in Chrome 153.0.8010.47

References

Related threats