CVE-2026-91716: High Use after free in Auth
Chromium CVE-2026-91716: Use after free
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases](https://chromereleases.googleblog.com/2026)) for more information.
— Microsoft
Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.4234.46 - Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 153.0.8010.47
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-85043
- CVE-2026-102324
- CVE-2026-87499
- CVE-2026-85052
- CVE-2026-84324
- CVE-2026-103630
- CVE-2026-95372
- CVE-2026-95351
- CVE-2026-17657
- CVE-2026-91708
- CVE-2026-95339
- CVE-2026-79201
- CVE-2026-95310
- CVE-2026-95356
- CVE-2026-19173
- CVE-2026-91737
- CVE-2026-79218
- CVE-2026-84325
- CVE-2026-91722
- CVE-2026-91724
- CVE-2026-91721
- CVE-2026-79219
- CVE-2026-19137
- CVE-2026-19170
- CVE-2026-87647
- CVE-2026-91736
- CVE-2026-87514
- CVE-2026-95313
- CVE-2026-91749
- CVE-2026-84357
- CVE-2026-85051
- CVE-2026-85053
- CVE-2026-87628
- CVE-2026-17666
- CVE-2026-79195
- CVE-2026-84349
- CVE-2026-78954
- CVE-2026-79174
- CVE-2026-79187
- CVE-2026-79274
- CVE-2026-78952
- CVE-2026-79078
Frequently Asked Questions
Who is exposed to exploitation?
Users of Google Chrome versions earlier than 153.0.8010.47 are exposed if they can be induced to load a crafted HTML page. The issue can be exploited remotely.
What level of access does an attacker need?
The attacker needs to deliver or cause the target to open a crafted HTML page. No local access or prior authentication requirement is stated.
What is the potential impact?
Successful exploitation can allow arbitrary code execution outside Chrome's sandbox.
How can I determine whether a system is affected?
Check the installed Google Chrome version. Versions prior to 153.0.8010.47 are affected according to the available information.