Medium · 6.4 Browsers CVE-2026-91728 CVE-2026-93372 CVE-2026-91716 CVE-2026-91710
Google Chrome Patches Eight High-Severity Vulnerabilities, Including Sandbox Escapes
Google has patched eight vulnerabilities in Chrome, several allowing arbitrary code execution outside the browser sandbox. Users should update to the latest stable version.
- Chrome Releases (Stable) vendor · view ↗
- NVD (NIST) database 3w ago · view ↗
- Chrome Releases (Stable) vendor · view ↗
- NVD (NIST) database 2w ago · view ↗
- NVD (NIST) database 3w ago · view ↗
- NVD (NIST) database 3w ago · view ↗
- NVD (NIST) database 2w ago · view ↗
- NVD (NIST) database 2w ago · view ↗
- NVD (NIST) database 3w ago · view ↗
- NVD (NIST) database 3w ago · view ↗
AI summary
Google released two separate Stable Channel updates for Chrome on desktop in September 2026, addressing a total of eight distinct vulnerabilities. All eight carry a CVSS base score of 9.6 and were rated High to Critical by Chromium's internal severity classification. Several of the flaws allow a remote attacker to execute arbitrary code outside the browser's sandbox via a specially crafted HTML page, making this a significant update for anyone running Chrome.
What happened
Google published two Stable Channel updates for Chrome on desktop in September 2026. The first update (fixed in version 153.0.8010.47) addressed six vulnerabilities: an integer overflow in V8 (CVE-2026-91728), a use after free in Auth (CVE-2026-91716), a use after free in WebAppInstalls (CVE-2026-91710), a use after free in Workers (CVE-2026-91749), a use after free in Core (CVE-2026-91718), and improper input validation in ANGLE (CVE-2026-91738). A second update, fixed in version 153.0.8010.52, addressed two further vulnerabilities on Chrome for Android: a buffer overflow in WebGL (CVE-2026-93372) and a use after free in Dawn (CVE-2026-93374). In all cases Google describes exploitation as occurring via a crafted HTML page.
Technical cause
The vulnerabilities span several different root causes. Most (CVE-2026-91716, CVE-2026-91710, CVE-2026-91749, CVE-2026-91718, CVE-2026-93374) are use-after-free bugs (CWE-416), a memory-safety class where a program continues to reference memory after it has been freed, which an attacker can exploit to corrupt memory and potentially execute code. CVE-2026-91728 is an integer overflow (CWE-190) in V8, Chrome's JavaScript engine. CVE-2026-93372 is a buffer overflow (CWE-121) in WebGL. CVE-2026-91738 is an improper input validation issue (CWE-20) in ANGLE, Chrome's graphics translation layer. The affected components span V8, Auth, WebAppInstalls, Workers, Core, ANGLE, WebGL, and Dawn — a broad set of browser subsystems.
Why it matters
Chromium itself classifies the integer overflow in V8 (CVE-2026-91728) as allowing code execution inside the sandbox, while the remaining seven vulnerabilities are described as allowing (or potentially allowing) code execution outside the sandbox. A sandbox escape is particularly serious because it means a successful exploit is not confined to the restricted browser process and could affect the broader system. All issues require a user to visit or interact with a crafted HTML page, meaning user interaction is required, but no authentication is needed for exploitation.
Who is affected
All users of Google Chrome on desktop are affected by the six vulnerabilities fixed in version 153.0.8010.47. Users of Google Chrome on Android are additionally affected by the two vulnerabilities fixed in version 153.0.8010.52. Given Chrome's extremely large install base, the practical exposure is wide.
Discovery and timeline
Google published the first set of fixes on September 15, 2026 and the second set on September 17, 2026, both via its official Chrome Releases blog for the Stable Channel. The fact package does not include information identifying who reported these vulnerabilities.
Affected versions
Chrome on desktop prior to version 153.0.8010.47 is affected by CVE-2026-91728, CVE-2026-91716, CVE-2026-91710, CVE-2026-91749, CVE-2026-91718, and CVE-2026-91738. Chrome on Android prior to version 153.0.8010.52 is affected by CVE-2026-93372 and CVE-2026-93374. Specific earlier affected version ranges were not provided in the fact package.
Fixes and mitigation
Google has released fixes for all eight vulnerabilities. Desktop Chrome users should update to version 153.0.8010.47 or later. Chrome for Android users should update to version 153.0.8010.52 or later. No workarounds or mitigations other than updating are described in the available source material.
Recommended action
Update Google Chrome to the latest stable version as soon as possible. Chrome typically updates automatically, but users and administrators should verify the installed version is 153.0.8010.47 (desktop) or 153.0.8010.52 (Android) or newer, and restart the browser to apply the update. Given the sandbox-escape potential of several of these flaws, prompt patching is advised.
PatchBriefing score
6.4 / 10 · Medium
Official CVSS: 9.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Why this score
Each vulnerability carries a CVSS base score of 9.6 (Critical range), reflecting network-based attack vector, low attack complexity, no privileges required, and high impact to confidentiality, integrity, and availability, combined with a scope change (S:C) indicating impact beyond the vulnerable component. The computed PatchBriefing score of 6.4 for each item reflects this high CVSS base score (contributing 5.28) plus additional weight for unauthenticated remote exploitability (0.6) and the very large install base of the affected product (0.5). No known exploitation in the wild, public exploit code, or EPSS data was available, which keeps the score below the maximum despite the high CVSS base.
Affected versions
- ≥ 153.0.8010.47
- patched
- ≥ 153.0.8010.52
- patched
- ≥ 153.0.8010.47
- patched
- ≥ 153.0.8010.47
- patched
- ≥ 153.0.8010.52
- patched
- ≥ 153.0.8010.47
- patched
- ≥ 153.0.8010.47
- patched
- ≥ 153.0.8010.47
- patched
Reported fixes
Google has released fixes for all eight vulnerabilities. Desktop Chrome users should update to version 153.0.8010.47 or later. Chrome for Android users should update to version 153.0.8010.52 or later. No workarounds or mitigations other than updating are described in the available source material.
How this was built
10 source records were collected, matched and used to prepare the report above.
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
Chrome Releases (Stable) vendor
-
NVD (NIST) database
-
NVD (NIST) database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email