Description
Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-15
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution outside the sandbox
Action: Immediate Patch
AI Analysis

Impact

Google Chrome versions prior to 153.0.8010.47 contain a use‑after‑free flaw in the Input component that enables a remote attacker who has compromised the renderer process to execute arbitrary code outside of the sandbox. The defect is a classic use‑after‑free error (CWE‑416) that can result in arbitrary code execution (CWE‑825). The vulnerability is rated high severity, indicating serious potential damage to confidentiality, integrity, and availability for affected users.

Affected Systems

The flaw affects all installations of Google Chrome (the Chromium browser) that are running a version earlier than 153.0.8010.47, regardless of operating system. The patch was released in the stable channel update for desktop browsers as referenced by the official Chrome release page.

Risk and Exploitability

The CVSS score for the issue is 8.3, confirming high impact. An EPSS score of less than 1% reflects a very low probability of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is remote, relying on a crafted HTML page that a user loads, which then triggers the already compromised process. No known public exploit exists, so the exploitation likelihood remains minimal but the potential impact is severe if the flaw is triggered.

Generated by OpenCVE AI on September 16, 2026 at 19:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.47 or later, the fixed release announced in the September 2026 stable channel update.
  • Enable automatic updates or maintain a manual update schedule to receive future security fixes promptly.
  • Ensure the operating system and all ancillary software remain current and install anti‑malware tools to reduce the likelihood that an attacker can compromise the renderer process before the sandbox protections are enforced.

Generated by OpenCVE AI on September 16, 2026 at 19:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: Chromium: Arbitrary code execution via use-after-free in Input
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}

threat_severity

Important


Tue, 15 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-17T03:56:05.383Z

Reserved: 2026-09-14T22:51:59.983Z

Link: CVE-2026-91724

cve-icon Vulnrichment

Updated: 2026-09-15T23:26:10.660Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-15T21:16:45.597

Modified: 2026-09-17T04:18:06.963

Link: CVE-2026-91724

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-15T20:41:27Z

Links: CVE-2026-91724 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T19:30:06Z

Weaknesses