Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-91722

CVE-2026-91722: Google Chrome Use After Free Vulnerability

CVE-2026-91722 is a use after free vulnerability in Google Chrome Input component that enables remote attackers to execute arbitrary code outside the sandbox. This article covers technical details, affected versions, and mitigation.

Updated:

CVE-2026-91722 Overview

CVE-2026-91722 is a use-after-free vulnerability [CWE-416] in the Input component of Google Chrome prior to version 153.0.8010.47. A remote attacker can exploit this flaw by convincing a user to visit a crafted HTML page. Successful exploitation allows arbitrary code execution outside the Chrome sandbox, giving attackers control over the underlying host process.

Chromium engineers classified this issue as Medium severity, while the National Vulnerability Database rates it High with a CVSS score of 8.8. The delta reflects the impact of sandbox escape combined with remote reachability through a browsed web page.

Critical Impact

Remote attackers can execute arbitrary code outside the Chrome sandbox through a single crafted web page visit, bypassing a core browser security boundary.

Affected Products

  • Google Chrome versions prior to 153.0.8010.47
  • Chromium-based browsers embedding the vulnerable Input component
  • Desktop Chrome Stable channel builds preceding the September 2026 update

Discovery Timeline

  • 2026-09-15 - CVE-2026-91722 published to NVD
  • 2026-09-17 - Last updated in NVD database

Technical Details for CVE-2026-91722

Vulnerability Analysis

The vulnerability resides in Chrome's Input subsystem, which handles input event routing between the renderer and browser processes. A use-after-free condition occurs when the code references a heap object after its memory has been released. An attacker who controls the object layout after free can redirect execution flow through a dangling pointer.

What makes this issue notable is the sandbox escape capability. Most renderer-side use-after-free bugs require chaining with a second flaw to break out of the Chrome sandbox. According to the Chromium advisory, this specific Input flaw enables arbitrary code execution outside sandbox boundaries directly.

Exploitation requires user interaction (UI:R), typically achieved by luring the target to a malicious page or a compromised site serving crafted content. No authentication or elevated privileges are needed on the target system.

Root Cause

The root cause is improper object lifetime management in the Input component. Code paths retain and dereference a pointer to a freed heap allocation. Attackers can groom the heap between the free and use operations to place attacker-controlled data at the reused address, corrupting internal state used by browser-process code.

Attack Vector

The attack vector is network-based delivery of a crafted HTML page. The attacker hosts malicious JavaScript and DOM structures that trigger the specific event sequence needed to free and then reuse the affected Input object. Because the flaw affects code paths that execute outside the sandboxed renderer, successful triggering yields code execution at the privilege level of the Chrome browser process.

No verified proof-of-concept exploit is publicly available. Technical details are tracked in Chromium Issue #554953456, which remains access-restricted per Google's standard disclosure policy.

Detection Methods for CVE-2026-91722

Indicators of Compromise

  • Chrome browser processes spawning unexpected child processes such as cmd.exe, powershell.exe, or /bin/sh after visiting untrusted pages
  • Outbound network connections from chrome.exe to previously unseen or low-reputation domains immediately after page load
  • Unexpected file writes or persistence artifacts created under the user profile shortly after browser activity

Detection Strategies

  • Inventory installed Chrome versions across the fleet and flag any host running a build below 153.0.8010.47
  • Correlate browser process telemetry with process-injection or memory-manipulation events using EDR behavioral analytics
  • Hunt for anomalous parent-child process relationships originating from Chrome renderer or browser processes

Monitoring Recommendations

  • Enable browser process command-line and child-process logging in endpoint telemetry
  • Monitor Chrome auto-update status to confirm timely rollout of the patched build across managed endpoints
  • Alert on execution of unsigned binaries dropped by Chrome process trees

How to Mitigate CVE-2026-91722

Immediate Actions Required

  • Update Google Chrome to version 153.0.8010.47 or later on all managed desktops immediately
  • Force-restart Chrome after applying the update to load the patched binaries into running processes
  • Validate enterprise Chrome update policies to ensure Stable channel deployment is not blocked or deferred

Patch Information

Google addressed CVE-2026-91722 in the Chrome Stable channel release documented in the Google Chrome Stable Update advisory. The fix is included in Chrome 153.0.8010.47 and later. Chromium-derived browsers (Edge, Brave, Opera, Vivaldi) should be updated once their vendors pick up the upstream patch.

Workarounds

  • Restrict browsing to trusted internal sites through proxy or DNS filtering until the patch is deployed
  • Deploy site isolation and enhanced Safe Browsing policies via Chrome enterprise management
  • Advise users to avoid clicking unsolicited links and to close Chrome fully to apply pending updates
bash
# Verify installed Chrome version on Windows
reg query "HKLM\Software\Google\Update\Clients\{8A69D345-D564-463C-AFF1-A69D9E530F96}" /v pv

# Verify installed Chrome version on Linux
google-chrome --version

# Verify installed Chrome version on macOS
/Applications/Google\ Chrome.app/Contents/MacOS/Google\ Chrome --version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.