Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.7 Browsers CVE-2026-91748 CVE-2026-91743 CVE-2026-91735 CVE-2026-91733

Google Chrome Stable Update Fixes Eight High-Severity Vulnerabilities

Google has released Chrome 153.0.8010.47 for desktop, fixing eight vulnerabilities rated High by Chromium's own severity classification, including use-after-free, race condition, and authorization bypass issues that could allow sandbox escape or code execution.

AI summary

Google has released a Stable Channel update for Chrome on desktop, version 153.0.8010.47, addressing eight separate vulnerabilities disclosed on the same day. Chromium's internal severity classification rates seven of these as High and one as Medium/Low depending on the specific issue. The vulnerabilities span several Chrome components, including Extensions, Core, WebUI, Skia, Input, and AppManifest, and several involve memory-safety or authorization weaknesses that could, under the right conditions, allow an attacker who has already compromised a renderer process to escape Chrome's sandbox. All eight issues are fixed in the same update.

What happened

Google published a Chrome Stable Channel update for desktop bringing the browser to version 153.0.8010.47. This release addresses eight distinct vulnerabilities identified as CVE-2026-91748, CVE-2026-91743, CVE-2026-91735, CVE-2026-91733, CVE-2026-91724, CVE-2026-91712, CVE-2026-91732, and CVE-2026-91719. The issues affect different parts of the browser: Extensions (two race conditions, one of which is specific to Mac), Core, WebUI, Skia (the graphics library), Input handling, and the AppManifest component, plus an XML-related code injection issue.

Technical causes

The vulnerabilities stem from several distinct root causes. CVE-2026-91748 and CVE-2026-91712 are race conditions (CWE-367) in the Extensions component on Mac. CVE-2026-91743 is a race condition (CWE-367) in Chrome's Core component. CVE-2026-91735 is an incorrect authorization issue (CWE-863) in WebUI. CVE-2026-91733 involves improper state validation (CWE-754) in Skia, Chrome's graphics rendering library, allowing out-of-sandbox memory reads. CVE-2026-91724 is a use-after-free (CWE-416) in Input handling. CVE-2026-91732 is a missing authorization issue (CWE-862) in AppManifest. CVE-2026-91719 is a code injection issue (CWE-94) related to XML processing. Most of these flaws require that an attacker has already compromised a renderer process, and several require user interaction or social engineering to be exploited further.

Why it matters

Several of these vulnerabilities allow an attacker who has already compromised Chrome's renderer process to escalate further and execute arbitrary code outside the sandbox, which is the primary security boundary protecting the rest of the system from malicious web content. This chaining potential makes the vulnerabilities significant even though each individually requires a renderer compromise as a prerequisite. CVE-2026-91733 differs in that it allows reading memory outside the sandbox rather than code execution. CVE-2026-91732 and CVE-2026-91719 involve bypassing the web origin policy, a core security mechanism that isolates content from different websites.

Who is affected

All users running Google Chrome on desktop prior to version 153.0.8010.47 are affected. Two of the eight vulnerabilities (CVE-2026-91748 and CVE-2026-91712) specifically affect the Mac version of Chrome's Extensions component.

Affected versions

Chrome versions prior to 153.0.8010.47 are affected by these vulnerabilities. The fact package does not specify the exact version ranges in which each vulnerability was introduced.

Fixes and mitigation

Google has fixed all eight vulnerabilities in Chrome 153.0.8010.47 for desktop. Chrome will typically update automatically; users and administrators should verify that their installation has updated to this version and restart the browser if prompted.

Recommended action

Update Google Chrome to version 153.0.8010.47 or later as soon as possible. Check the browser's "About Chrome" page to confirm the update has been applied, and restart the browser to complete the update. There are no indications in this fact package that any of these vulnerabilities are being actively exploited, but prompt patching is recommended given the potential for sandbox escape.

PatchBriefing score

5.7 / 10 · Medium

Official CVSS: 8.3

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Why this score

The patchwire scores for these vulnerabilities (5.6–5.7) are driven primarily by their CVSS base scores of 8.1–8.3, reflecting network-exploitable issues with high confidentiality and/or integrity impact. Scores also account for a small contribution from the unauthenticated remote attack vector and the large install base of Chrome (product popularity). None of these vulnerabilities are listed as known exploited or as having public exploit code, and no EPSS score was available, so those factors contributed nothing to the final score. A fix is available for all issues, so the "no fix available" penalty does not apply.

Affected versions

≥ 153.0.8010.47
patched
≥ 153.0.8010.47
patched
≥ 153.0.8010.47
patched
≥ 153.0.8010.47
patched
≥ 153.0.8010.47
patched
≥ 153.0.8010.47
patched
≥ 153.0.8010.47
patched
≥ 153.0.8010.47
patched

Reported fixes

Google has fixed all eight vulnerabilities in Chrome 153.0.8010.47 for desktop. Chrome will typically update automatically; users and administrators should verify that their installation has updated to this version and restart the browser if prompted.

How this was built

9 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome Stable Update Fixes Eight High-Severity Vulnerabilities
1 article · 9 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email