
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-91745 is a use-after-free vulnerability in the V8 JavaScript engine of Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. It affects all Google Chrome versions prior to 153.0.8010.47. The vulnerability was reported to Google on September 8, 2026, and a patch was released on September 15, 2026, as part of a broader update addressing 42 security issues. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Feedly).
The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), rooted in improper memory management within Chrome's V8 JavaScript engine. A use-after-free condition occurs when V8 continues to reference memory that has already been freed, allowing an attacker to craft a malicious HTML page that triggers this condition and potentially controls the freed memory region to redirect execution flow. Exploitation requires user interaction — specifically, a victim visiting or being redirected to a malicious web page — but requires no authentication or special privileges from the attacker. The Chromium issue tracker references bug ID 558734727 for this vulnerability (Chrome Releases, Feedly).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox, impacting confidentiality, integrity, and availability at a high level. While execution is constrained to the sandbox environment, a successful exploit could serve as a stepping stone for a sandbox escape when chained with additional vulnerabilities, potentially leading to full system compromise. The attack surface is broad, as any user running a vulnerable Chrome version who visits a malicious or compromised website is at risk (Feedly, Chrome Releases).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The NVD SSVC assessment also indicates exploitation status as "none" at the time of publication. The EPSS score is 0.0, reflecting a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Google has released a patch in Chrome version 153.0.8010.47 for Linux and 153.0.8010.47/.48 for Windows and Mac, which addresses this vulnerability along with 41 other security issues. Users should update Google Chrome to version 153.0.8010.47 or later immediately by navigating to Settings > Help > About Google Chrome. Enterprise administrators should enforce Chrome updates via browser management policies (e.g., Google Admin Console or Group Policy) to ensure fleet-wide coverage. No configuration-based workaround is available; updating is the only remediation (Chrome Releases).
The Chrome 153 update, which includes the fix for CVE-2026-91745, received coverage from several cybersecurity news outlets highlighting the scale of the release — 42 security fixes including three critical vulnerabilities. Coverage noted the breadth of the patch batch as significant (Cryptika, CyberSecurityNews, GBHackers). No specific researcher commentary or notable social media discussion focused exclusively on CVE-2026-91745 has been identified.
Fix availability across major Linux distributions and their releases.
bookworm
chromium: 153.0.8010.47-1
sid
chromium: 153.0.8010.47-1
trixie
chromium: 153.0.8010.47-2~deb13u1
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."