CVE-2026-91727: High severity Google Chrome for Mac vulnerability
Chromium CVE-2026-91727: Incorrect reference resolution
Other sources
Incorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases](https://chromereleases.googleblog.com/2026)) for more information.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.4234.46 - Upgrade
Upgrade
Google Chrome / Chromium-based browsers (Extensions on macOS)to a version that resolves this vulnerability.Fixed in 153.0.8010.47
Event History
Frequently Asked Questions
Who is exposed to this issue?
Google Chrome for Mac installations running versions earlier than 153.0.8010.47 are affected. Exploitation requires the attacker to have already compromised the Chrome renderer process and to use a local program.
What level of access does an attacker need?
This is not described as an initial remote compromise. The attacker must first compromise the renderer process, then can leverage the issue locally to execute arbitrary code outside Chrome's sandbox.
What is the impact if exploitation succeeds?
A successful exploit allows arbitrary code execution outside the Chrome sandbox. The issue is rated High by Chromium.
What should be updated?
Update Google Chrome for Mac to version 153.0.8010.47 or later.