Executive brief
Google Chrome is a web browser used by billions of people to access websites and web applications. A use-after-free vulnerability in Chrome's DOM (Document Object Model) handling allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious website. Successful exploitation could lead to account compromise, data theft, or malware installation.
Technical details
A use-after-free vulnerability exists in Google Chrome's DOM implementation prior to version 153.0.8010.47. The vulnerability occurs when the browser attempts to access memory that has been freed, allowing an attacker to execute arbitrary code within the browser sandbox. An attacker can exploit this vulnerability by crafting a malicious HTML page and convincing a user to visit it via a network vector (no authentication or special user interaction beyond browsing is required). The vulnerability is fixed in Chrome version 153.0.8010.47 and later.
Affected products
- Google Chrome prior to 153.0.8010.47
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fixed in version 153.0.8010.47