Description
Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Google Chrome contains a use‑after‑free flaw in the DOM that lets an attacker run arbitrary code inside the sandbox when a crafted HTML page is loaded. The vulnerability is a classic memory‑corruption error (CWE‑416) that can compromise confidentiality, integrity, and availability of the affected system by granting the attacker the privileges of the sandboxed process. The impact is that arbitrary code execution within the sandbox environment is possible.

Affected Systems

All users running Google Chrome versions older than 153.0.8010.47 are vulnerable. The issue exists in the stable channel and applies to the standard desktop build of Chrome affected.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, but the EPSS score of less than 1% suggests that exploitation is currently unlikely is not listed in the CISA KEV catalog. The attacker must supply a malicious HTML page that a user opens; no external network or attack vector is browser‑based. Because the code runs inside the sandbox, the scope is limited to the sandboxed process.

Generated by OpenCVE AI on September 16, 2026 at 19:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Chrome update to version 153.0.8010.47 or later
  • Configure Chrome to auto‑update or enforce the update via enterprise policies
  • Restrict users from opening unknown or untrusted HTML files through network or group policies

Generated by OpenCVE AI on September 16, 2026 at 19:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Title Chrome Use‑After‑Free in DOM Enables Remote Code Execution via Crafted HTML

Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-17T03:56:03.124Z

Reserved: 2026-09-14T22:52:32.387Z

Link: CVE-2026-91736

cve-icon Vulnrichment

Updated: 2026-09-15T23:47:03.339Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T21:16:47.147

Modified: 2026-09-17T04:18:09.263

Link: CVE-2026-91736

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T20:00:05Z

Weaknesses