Medium · 5.2 Browsers CVE-2026-91727 CVE-2026-93375 CVE-2026-91734
Google Chrome Patches Three High-Severity Sandbox Escape Vulnerabilities
Google has fixed three high-severity Chrome vulnerabilities (CVE-2026-91727, CVE-2026-93375, CVE-2026-91734) that could allow a local attacker who has already compromised the renderer process to execute code outside Chrome's sandbox. Updates to versions 153.0.8010.47 and 153.0.8010.52 are available.
AI summary
Google has released stable channel updates for Chrome that address three separate high-severity vulnerabilities. Each flaw could allow an attacker who already has limited code execution inside Chrome's renderer process to break out of the sandbox and run arbitrary code on the underlying system. All three issues were disclosed and fixed through Google's standard Chrome stable channel update process.
What happened
Google published Chrome stable channel updates fixing three vulnerabilities: CVE-2026-91727 (incorrect reference resolution in Extensions, affecting Chrome on Mac), CVE-2026-93375 (incorrect reference resolution in Tracing, affecting Chrome on Windows), and CVE-2026-91734 (incorrect authorization in Core, affecting Chrome on Windows). Google rates all three as 'High' severity in its own Chromium severity scale.
Technical cause
CVE-2026-91727 and CVE-2026-93375 both stem from incorrect reference resolution (CWE-706), one in the Extensions component and one in the Tracing component. CVE-2026-91734 is caused by incorrect authorization (CWE-863) in Chrome's Core component. In all three cases, the underlying weakness permits a local attacker who has already compromised the renderer process via a local program to escape Chrome's sandbox and execute arbitrary code.
Why it matters
A sandbox escape significantly raises the impact of an initial renderer compromise: instead of being confined to Chrome's restricted process, an attacker could gain broader code execution on the host. These vulnerabilities require the attacker to already have a foothold in the renderer process (e.g. via a separate exploited bug or malicious local program), so they are not remotely exploitable on their own, but they remove a key defense-in-depth barrier once that foothold exists.
Who is affected
CVE-2026-91727 affects Google Chrome on Mac prior to version 153.0.8010.47. CVE-2026-93375 affects Google Chrome on Windows prior to version 153.0.8010.52. CVE-2026-91734 affects Google Chrome on Windows prior to version 153.0.8010.47. The fact package does not specify whether Linux or other platforms are affected by these specific CVEs.
Affected versions
Google Chrome versions prior to 153.0.8010.47 (CVE-2026-91727 on Mac, CVE-2026-91734 on Windows) and prior to 153.0.8010.52 (CVE-2026-93375 on Windows) are affected. No specific starting version for the vulnerable range was provided in the fact package.
Fixes and mitigation
Google has released fixed versions through the Chrome stable channel: version 153.0.8010.47 resolves CVE-2026-91727 and CVE-2026-91734, and version 153.0.8010.52 resolves CVE-2026-93375. Chrome typically applies these updates automatically on restart, but users and administrators should verify the installed version.
Recommended action
Update Google Chrome to version 153.0.8010.47 or later to address CVE-2026-91727 (Mac) and CVE-2026-91734 (Windows), and to version 153.0.8010.52 or later to address CVE-2026-93375 (Windows). Restart the browser after updating to ensure the fix is applied, and confirm the installed version via Chrome's About page.
PatchBriefing score
5.2 / 10 · Medium
Official CVSS: 8.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Why this score
Each vulnerability carries a patchwire_score around 4.8–5.2, driven primarily by CVSS base scores of 8.1 (CVE-2026-91727, CVE-2026-93375) and 7.4 (CVE-2026-91734). All require local access and a prior renderer compromise (AV:L, PR:N, no user interaction), with no evidence of known exploitation or public exploit code. Product popularity (Chrome's large install base) adds a modest contribution, but the lack of confirmed in-the-wild exploitation and the requirement for an existing local foothold keep the scores in the moderate-high range rather than critical.
Affected versions
- ≥ 153.0.8010.47
- patched
- ≥ 153.0.8010.52
- patched
- ≥ 153.0.8010.47
- patched
Reported fixes
Google has released fixed versions through the Chrome stable channel: version 153.0.8010.47 resolves CVE-2026-91727 and CVE-2026-91734, and version 153.0.8010.52 resolves CVE-2026-93375. Chrome typically applies these updates automatically on restart, but users and administrators should verify the installed version.
How this was built
5 source records were collected, matched and used to prepare the report above.
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email