Wednesday, September 16, 2026
Follow on LinkedIn

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the browser, including three bugs rated Critical. The Stable channel is moving to 153.0.8010.47/.48 for Windows and macOS and 153.0.8010.47 for Linux, with the update rolling out gradually over the coming days and weeks.

CVE-2026-91721 is a use-after-free vulnerability in Chrome’s Internals component, reported by researcher xinyang, while CVE-2026-91749 is a use-after-free flaw affecting Workers, reported by WinD39–Huynh Dinh Vu. The third, CVE-2026-91726, is an out-of-bounds read in WebGL identified internally by Google.

Use-after-free flaws arise when software continues referencing memory after that memory has been released, potentially creating a dangling pointer that attackers can manipulate.

Depending on the affected process, surrounding protections, and available exploit primitives, this bug class can cause crashes, expose data, or enable arbitrary code execution.

Google Chrome Fixes 42 Flaws

The WebGL flaw is also significant because out-of-bounds access can make an application read beyond an intended memory boundary. Google has not provided exploit scenarios or technical details for the three Critical vulnerabilities, and its bulletin does not state that any of the 42 newly patched issues are being actively exploited.

Chrome 153 also addresses 27 High-severity vulnerabilities spanning some of the browser’s most security-sensitive components. These include use-after-free bugs in Input, Skia, DOM, WebAppInstalls, Core, Auth, DigitalCredentials, PDF and V8, alongside type-confusion issues in Compositing, CacheStorage and ServiceWorker. Google also fixed integer overflows in V8 and Compositing, race conditions in Core, PlatformIntegration, Extensions and Network, and an out-of-bounds write in ServiceWorker.

Authorization and validation weaknesses expand the scope beyond memory corruption. The update corrects authorization problems in Core, Android and WebUI, an incorrect reference-resolution issue in Extensions, uninitialized-resource bugs in ANGLE and Skia, and improper state validation in Skia.

This breadth demonstrates the complexity of securing a modern browser that handles graphics, scripts, extensions, documents, credentials and untrusted web content within interconnected processes.

The remaining patches cover ten Medium-severity vulnerabilities and one Low-severity issue. They include authorization failures, observable discrepancies in Fonts and CSS, improper input validation in ANGLE, incomplete GetUserMedia cleanup and another Input use-after-free. The Low-severity CVE-2026-91719 is a code-injection vulnerability in XML reported by Zabith Mohammed.

Google awarded Hafiizh $1,500 for reporting CVE-2026-91724, a High-severity Input use-after-free vulnerability. Jihyeon Jeong of Seoul National University’s Compsec Lab received $1,000 for CVE-2026-91728, an integer overflow in V8.

Rewards for several externally reported findings remain marked “TBD,” indicating that amounts had not been finalized when Google published the advisory.

CVESeverityVulnerabilityComponent
CVE-2026-91726 CriticalOut-of-bounds readWebGL
CVE-2026-91721 CriticalUse-after-freeInternals
CVE-2026-91749 CriticalUse-after-freeWorkers
CVE-2026-91724 HighUse-after-freeInput
CVE-2026-91728 HighInteger overflowV8
CVE-2026-91734 HighIncorrect authorizationCore
CVE-2026-91727 HighIncorrect reference resolutionExtensions
CVE-2026-91743 HighRace conditionCore
CVE-2026-91744 HighRace conditionPlatformIntegration
CVE-2026-91712 HighRace conditionExtensions
CVE-2026-91748 HighRace conditionExtensions
CVE-2026-91720 HighUninitialized resourceANGLE
CVE-2026-91731 HighType confusionCompositing
CVE-2026-91747 HighUse-after-freeSkia
CVE-2026-91733 HighImproper state validationSkia
CVE-2026-91741 HighType confusionCacheStorage
CVE-2026-91709 HighType confusionServiceWorker
CVE-2026-91717 HighMissing authorizationAndroid
CVE-2026-91735 HighIncorrect authorizationWebUI
CVE-2026-91708 HighRace conditionNetwork
CVE-2026-91736 HighUse-after-freeDOM
CVE-2026-91740 HighUninitialized resourceSkia
CVE-2026-91710 HighUse-after-freeWebAppInstalls
CVE-2026-91718 HighUse-after-freeCore
CVE-2026-91716 HighUse-after-freeAuth
CVE-2026-91746 HighInteger overflowCompositing
CVE-2026-91729 HighUse-after-freeDigitalCredentials
CVE-2026-91737 HighUse-after-freePDF
CVE-2026-91711 HighOut-of-bounds writeServiceWorker
CVE-2026-91715 HighType confusionServiceWorker
CVE-2026-91745 HighUse-after-freeV8
CVE-2026-91723 MediumRace conditionWebAppInstalls
CVE-2026-91732 MediumMissing authorizationAppManifest
CVE-2026-91742 MediumConfused deputyPriceTracking
CVE-2026-91714 MediumObservable discrepancyFonts
CVE-2026-91725 MediumObservable discrepancyCSS
CVE-2026-91739 MediumMissing authorizationTransactions Platform
CVE-2026-91713 MediumMissing authorizationBrowser
CVE-2026-91738 MediumImproper input validationANGLE
CVE-2026-91730 MediumIncomplete cleanupGetUserMedia
CVE-2026-91722 MediumUse-after-freeInput
CVE-2026-91719 LowCode injectionXML

Detailed bug links may remain restricted until most users receive the fixes. Google may preserve restrictions longer when a vulnerability exists in a third-party library on which other, not-yet-patched projects depend, limiting attackers’ access to technical information during deployment.

Users should open Chrome’s menu and navigate to Help and then About Google Chrome, allow the update to install, and select Relaunch. Google says Chrome normally updates in the background, but a restart is required to apply a pending release.

Enterprise administrators should accelerate deployment, confirm the running version across managed endpoints and investigate devices held back by update policies or pending restarts.

Google supports centralized Chrome update management through Group Policy on eligible Windows devices, while administrators can review applied settings at chrome://policy. On Windows, policy controls apply only to domain-joined or MDM-managed devices, so unmanaged systems and rarely connected endpoints require separate checks.

Security teams should inventory duplicate installations and alternate channels, enforce an update deadline, and confirm that users have relaunched the browser. Merely enabling automatic updates does not prove that the patched binary is running across the entire fleet.

Google credits AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer and AFL with detecting many security bugs. Given the number and severity of the fixes, users should verify installation of Chrome 153.0.8010.47/.48 on Windows or macOS and 153.0.8010.47 on Linux rather than waiting for the staged rollout to finish.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baran
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Cyber Security Guide

Latest Cyber News

Expert Talks