Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.9 Browsers CVE-2026-93377 CVE-2026-91722 CVE-2026-91715 CVE-2026-93382

Google Chrome Patches Seven High-Severity Memory Safety Vulnerabilities

Google shipped two Chrome stable channel updates in September 2026 fixing seven vulnerabilities — type confusion, use-after-free, and out-of-bounds write bugs in V8, ServiceWorker, PDFium, Compositing, and Input/Internals components — all requiring user interaction via a crafted HTML page.

AI summary

Google released two Chrome Stable Channel updates in September 2026 that together address seven distinct memory-safety vulnerabilities. Each flaw is rated 8.8 (CVSS 3.1) and involves a remote attacker crafting a malicious HTML page to trigger code execution, with user interaction required to view or load the page. The issues span different browser components, including the V8 JavaScript engine, PDFium, ServiceWorker, Compositing, Input, and Internals.

Seven Memory-Safety Bugs Fixed Across Two Updates

Google published two separate Stable Channel updates for Chrome Desktop in September 2026. The first, released around September 15, 2026, addressed five vulnerabilities fixed in version 153.0.8010.47: CVE-2026-91711 (out-of-bounds write in ServiceWorker), CVE-2026-91715 (type confusion in ServiceWorker), CVE-2026-91721 (use-after-free in Internals), CVE-2026-91722 (use-after-free in Input), and CVE-2026-91731 (type confusion in Compositing). The second update, released around September 17, 2026, addressed two further vulnerabilities fixed in version 153.0.8010.52: CVE-2026-93377 (type confusion in V8) and CVE-2026-93382 (use-after-free in PDFium). All seven advisories describe exploitation via a specially crafted HTML page.

Type Confusion, Use-After-Free, and Out-of-Bounds Write

The seven vulnerabilities fall into three technical categories. Type confusion issues (CWE-843) affect V8 (CVE-2026-93377), ServiceWorker (CVE-2026-91715), and Compositing (CVE-2026-91731), where code treats an object as a different, incompatible type, potentially allowing memory corruption. Use-after-free issues (CWE-416) affect PDFium (CVE-2026-93382), Internals (CVE-2026-91721), and Input (CVE-2026-91722), where memory is accessed after it has been freed. An out-of-bounds write issue (CWE-787) affects ServiceWorker (CVE-2026-91711), allowing data to be written outside the bounds of allocated memory. Chromium rated the severity of these individually as High (CVE-2026-93377, CVE-2026-93382, CVE-2026-91715, CVE-2026-91731, CVE-2026-91711), Medium (CVE-2026-91722), and Critical (CVE-2026-91721).

Potential for Sandbox Escape and Arbitrary Code Execution

Most of these vulnerabilities allow arbitrary code execution inside the Chrome sandbox via a crafted HTML page. Two of them — CVE-2026-91721 and CVE-2026-91722 — are described as potentially allowing code execution outside the sandbox, which would represent a more serious compromise since it could affect the host system beyond the browser's isolated environment. CVE-2026-93377 additionally notes that exploitation could involve social engineering as part of the attack chain.

All Chrome Desktop Users on Affected Versions

These vulnerabilities affect Google Chrome on desktop prior to the respective fixed versions. The fact package does not specify particular operating systems or editions, so this briefing treats the affected scope as Chrome Desktop generally, per the vendor's release notes.

Timeline

The first set of five vulnerabilities (CVE-2026-91711, -91715, -91721, -91722, -91731) was published around September 15, 2026, with the fix in version 153.0.8010.47. The second set of two vulnerabilities (CVE-2026-93377, -93382) was published around September 17, 2026, with the fix in version 153.0.8010.52. No discoverer or reporting credit is included in the fact package, and this briefing does not attribute discovery to any individual or group.

Versions Affected and Fixed

Google Chrome versions prior to 153.0.8010.47 are affected by CVE-2026-91711, CVE-2026-91715, CVE-2026-91721, CVE-2026-91722, and CVE-2026-91731; these are fixed in 153.0.8010.47. Google Chrome versions prior to 153.0.8010.52 are affected by CVE-2026-93377 and CVE-2026-93382; these are fixed in 153.0.8010.52.

Fixes Available via Standard Chrome Update

Fixes for all seven vulnerabilities are available through Google's standard Chrome Stable Channel release mechanism. Users running a version prior to 153.0.8010.52 should update, as this version includes fixes for all seven issues described here (153.0.8010.52 supersedes 153.0.8010.47 chronologically).

Update Chrome Now

Site owners and developers should ensure Chrome is updated to version 153.0.8010.52 or later on all desktop systems. Chrome typically updates automatically on restart, but administrators managing fleets of machines should verify update deployment, particularly given that several of these flaws permit remote code execution via a web page with no further privileges required.

PatchBriefing score

5.9 / 10 · Medium

Official CVSS: 8.8

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Why this score

Each of these seven vulnerabilities carries a CVSS 3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), reflecting network-exploitable, low-complexity attacks requiring no privileges but some user interaction, with high impact to confidentiality, integrity, and availability. The computed PatchBriefing score of 5.9 for each advisory reflects the high CVSS base score (contributing 4.84), the unauthenticated remote attack vector (contributing 0.6), and Chrome's very large install base (contributing 0.5). None of these vulnerabilities are currently flagged as known exploited, associated with ransomware activity, or having a public exploit available, and no EPSS score was provided in the fact package.

Affected versions

≥ 153.0.8010.52
patched
≥ 153.0.8010.47
patched
≥ 153.0.8010.47
patched
≥ 153.0.8010.52
patched
≥ 153.0.8010.47
patched
≥ 153.0.8010.47
patched
≥ 153.0.8010.47
patched

Reported fixes

Fixes for all seven vulnerabilities are available through Google's standard Chrome Stable Channel release mechanism. Users running a version prior to 153.0.8010.52 should update, as this version includes fixes for all seven issues described here (153.0.8010.52 supersedes 153.0.8010.47 chronologically).

How this was built

9 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome Patches Seven High-Severity Memory Safety Vulnerabilities
1 article · 9 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email