Impact
CVE-2026-91734 reveals an incorrect authorization check in the Core component of Google Chrome running on Windows. The flaw allows a local attacker to execute arbitrary code outside the browser sandbox using a locally run program, giving them full system control. This weakness corresponds to CWE-863 and can lead to complete compromise of confidentiality, integrity, and availability on affected machines.
Affected Systems
Affected systems are Windows machines that run Google Chrome versions earlier than 153.0.8010.47. All users of these browsers are vulnerable until the patch is applied.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity, while the EPSS score of less than 1 % suggests a low probability of exploitation in the wild. Because the issue requires local access to a program that can load faulty Chrome binaries, the risk is primarily for users who inadvertently run malicious software on the local machine. The vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment