Description
Use after free in PDF in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

A use‑after‑free bug in Google Chrome’s PDF rendering engine allows an attacker to execute arbitrary code within the browser’s sandbox by loading a specially crafted HTML page that references a PDF. If the page is opened in a victim’s browser, the freed memory can be accessed and overwritten, enabling the attacker to run malicious code inside the confined environment of the browser sandbox.

Affected Systems

Google Chrome versions earlier than 153.0.8010.47 on any operating system are affected.

Risk and Exploitability

The vulnerability has a CVSS score of 8.8, indicating high severity. Its EPSS score is less than 1%, showing a low probability of exploitation in the current environment, and it is not listed in the CISA KEV catalog. The likely attack vector is a remote user opening a malicious HTML page that triggers the PDF rendering flaw, which then permits code execution inside the sandboxed browser process.

Generated by OpenCVE AI on September 16, 2026 at 20:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome 153.0.8010.47 or a newer release that contains the fix.
  • Use a dedicated PDF viewer outside of Chrome for documents from untrusted or unknown sources.
  • Keep Chrome periodically updated and monitor official vendor advisories for future security releases.

Generated by OpenCVE AI on September 16, 2026 at 20:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome PDF Renderer Enables Remote Code Execution from Crafted HTML Page

Wed, 16 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Use after free in PDF in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-17T03:55:56.782Z

Reserved: 2026-09-14T22:52:38.077Z

Link: CVE-2026-91737

cve-icon Vulnrichment

Updated: 2026-09-16T10:16:59.777Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T21:16:47.270

Modified: 2026-09-17T04:18:09.430

Link: CVE-2026-91737

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T21:00:08Z

Weaknesses