Medium · 5.9 Browsers CVE-2026-93377 CVE-2026-91722 CVE-2026-91715 CVE-2026-93382
Google Chrome Patches Seven High-Severity Memory Safety Vulnerabilities
Google shipped two Chrome stable channel updates in September 2026 fixing seven vulnerabilities — type confusion, use-after-free, and out-of-bounds write bugs in V8, ServiceWorker, PDFium, Compositing, and Input/Internals components — all requiring user interaction via a crafted HTML page.
- Chrome Releases (Stable) vendor · view ↗
- NVD (NIST) database 2w ago · view ↗
- Chrome Releases (Stable) vendor · view ↗
- NVD (NIST) database 3w ago · view ↗
- NVD (NIST) database 3w ago · view ↗
- NVD (NIST) database 3w ago · view ↗
- NVD (NIST) database 3w ago · view ↗
- NVD (NIST) database 3w ago · view ↗
- NVD (NIST) database 3w ago · view ↗
AI summary
Google released two Chrome Stable Channel updates in September 2026 that together address seven distinct memory-safety vulnerabilities. Each flaw is rated 8.8 (CVSS 3.1) and involves a remote attacker crafting a malicious HTML page to trigger code execution, with user interaction required to view or load the page. The issues span different browser components, including the V8 JavaScript engine, PDFium, ServiceWorker, Compositing, Input, and Internals.
Seven Memory-Safety Bugs Fixed Across Two Updates
Google published two separate Stable Channel updates for Chrome Desktop in September 2026. The first, released around September 15, 2026, addressed five vulnerabilities fixed in version 153.0.8010.47: CVE-2026-91711 (out-of-bounds write in ServiceWorker), CVE-2026-91715 (type confusion in ServiceWorker), CVE-2026-91721 (use-after-free in Internals), CVE-2026-91722 (use-after-free in Input), and CVE-2026-91731 (type confusion in Compositing). The second update, released around September 17, 2026, addressed two further vulnerabilities fixed in version 153.0.8010.52: CVE-2026-93377 (type confusion in V8) and CVE-2026-93382 (use-after-free in PDFium). All seven advisories describe exploitation via a specially crafted HTML page.
Type Confusion, Use-After-Free, and Out-of-Bounds Write
The seven vulnerabilities fall into three technical categories. Type confusion issues (CWE-843) affect V8 (CVE-2026-93377), ServiceWorker (CVE-2026-91715), and Compositing (CVE-2026-91731), where code treats an object as a different, incompatible type, potentially allowing memory corruption. Use-after-free issues (CWE-416) affect PDFium (CVE-2026-93382), Internals (CVE-2026-91721), and Input (CVE-2026-91722), where memory is accessed after it has been freed. An out-of-bounds write issue (CWE-787) affects ServiceWorker (CVE-2026-91711), allowing data to be written outside the bounds of allocated memory. Chromium rated the severity of these individually as High (CVE-2026-93377, CVE-2026-93382, CVE-2026-91715, CVE-2026-91731, CVE-2026-91711), Medium (CVE-2026-91722), and Critical (CVE-2026-91721).
Potential for Sandbox Escape and Arbitrary Code Execution
Most of these vulnerabilities allow arbitrary code execution inside the Chrome sandbox via a crafted HTML page. Two of them — CVE-2026-91721 and CVE-2026-91722 — are described as potentially allowing code execution outside the sandbox, which would represent a more serious compromise since it could affect the host system beyond the browser's isolated environment. CVE-2026-93377 additionally notes that exploitation could involve social engineering as part of the attack chain.
All Chrome Desktop Users on Affected Versions
These vulnerabilities affect Google Chrome on desktop prior to the respective fixed versions. The fact package does not specify particular operating systems or editions, so this briefing treats the affected scope as Chrome Desktop generally, per the vendor's release notes.
Timeline
The first set of five vulnerabilities (CVE-2026-91711, -91715, -91721, -91722, -91731) was published around September 15, 2026, with the fix in version 153.0.8010.47. The second set of two vulnerabilities (CVE-2026-93377, -93382) was published around September 17, 2026, with the fix in version 153.0.8010.52. No discoverer or reporting credit is included in the fact package, and this briefing does not attribute discovery to any individual or group.
Versions Affected and Fixed
Google Chrome versions prior to 153.0.8010.47 are affected by CVE-2026-91711, CVE-2026-91715, CVE-2026-91721, CVE-2026-91722, and CVE-2026-91731; these are fixed in 153.0.8010.47. Google Chrome versions prior to 153.0.8010.52 are affected by CVE-2026-93377 and CVE-2026-93382; these are fixed in 153.0.8010.52.
Fixes Available via Standard Chrome Update
Fixes for all seven vulnerabilities are available through Google's standard Chrome Stable Channel release mechanism. Users running a version prior to 153.0.8010.52 should update, as this version includes fixes for all seven issues described here (153.0.8010.52 supersedes 153.0.8010.47 chronologically).
Update Chrome Now
Site owners and developers should ensure Chrome is updated to version 153.0.8010.52 or later on all desktop systems. Chrome typically updates automatically on restart, but administrators managing fleets of machines should verify update deployment, particularly given that several of these flaws permit remote code execution via a web page with no further privileges required.
PatchBriefing score
5.9 / 10 · Medium
Official CVSS: 8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Why this score
Each of these seven vulnerabilities carries a CVSS 3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), reflecting network-exploitable, low-complexity attacks requiring no privileges but some user interaction, with high impact to confidentiality, integrity, and availability. The computed PatchBriefing score of 5.9 for each advisory reflects the high CVSS base score (contributing 4.84), the unauthenticated remote attack vector (contributing 0.6), and Chrome's very large install base (contributing 0.5). None of these vulnerabilities are currently flagged as known exploited, associated with ransomware activity, or having a public exploit available, and no EPSS score was provided in the fact package.
Affected versions
- ≥ 153.0.8010.52
- patched
- ≥ 153.0.8010.47
- patched
- ≥ 153.0.8010.47
- patched
- ≥ 153.0.8010.52
- patched
- ≥ 153.0.8010.47
- patched
- ≥ 153.0.8010.47
- patched
- ≥ 153.0.8010.47
- patched
Reported fixes
Fixes for all seven vulnerabilities are available through Google's standard Chrome Stable Channel release mechanism. Users running a version prior to 153.0.8010.52 should update, as this version includes fixes for all seven issues described here (153.0.8010.52 supersedes 153.0.8010.47 chronologically).
How this was built
9 source records were collected, matched and used to prepare the report above.
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email