Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the browser, including three bugs rated Critical. The Stable channel is moving to 153.0.8010.47/.48 for Windows and macOS and 153.0.8010.47 for Linux, with the update rolling out gradually over the coming days and weeks.
CVE-2026-91721 is a use-after-free vulnerability in Chrome’s Internals component, reported by researcher xinyang, while CVE-2026-91749 is a use-after-free flaw affecting Workers, reported by WinD39–Huynh Dinh Vu. The third, CVE-2026-91726, is an out-of-bounds read in WebGL identified internally by Google.
Use-after-free flaws arise when software continues referencing memory after that memory has been released, potentially creating a dangling pointer that attackers can manipulate.
Depending on the affected process, surrounding protections, and available exploit primitives, this bug class can cause crashes, expose data, or enable arbitrary code execution.
The WebGL flaw is also significant because out-of-bounds access can make an application read beyond an intended memory boundary. Google has not provided exploit scenarios or technical details for the three Critical vulnerabilities, and its bulletin does not state that any of the 42 newly patched issues are being actively exploited.
Chrome 153 also addresses 27 High-severity vulnerabilities spanning some of the browser’s most security-sensitive components. These include use-after-free bugs in Input, Skia, DOM, WebAppInstalls, Core, Auth, DigitalCredentials, PDF and V8, alongside type-confusion issues in Compositing, CacheStorage and ServiceWorker. Google also fixed integer overflows in V8 and Compositing, race conditions in Core, PlatformIntegration, Extensions and Network, and an out-of-bounds write in ServiceWorker.
Authorization and validation weaknesses expand the scope beyond memory corruption. The update corrects authorization problems in Core, Android and WebUI, an incorrect reference-resolution issue in Extensions, uninitialized-resource bugs in ANGLE and Skia, and improper state validation in Skia.
This breadth demonstrates the complexity of securing a modern browser that handles graphics, scripts, extensions, documents, credentials and untrusted web content within interconnected processes.
The remaining patches cover ten Medium-severity vulnerabilities and one Low-severity issue. They include authorization failures, observable discrepancies in Fonts and CSS, improper input validation in ANGLE, incomplete GetUserMedia cleanup and another Input use-after-free. The Low-severity CVE-2026-91719 is a code-injection vulnerability in XML reported by Zabith Mohammed.
Google awarded Hafiizh $1,500 for reporting CVE-2026-91724, a High-severity Input use-after-free vulnerability. Jihyeon Jeong of Seoul National University’s Compsec Lab received $1,000 for CVE-2026-91728, an integer overflow in V8.
Rewards for several externally reported findings remain marked “TBD,” indicating that amounts had not been finalized when Google published the advisory.
| CVE | Severity | Vulnerability | Component |
|---|---|---|---|
| CVE-2026-91726 | Critical | Out-of-bounds read | WebGL |
| CVE-2026-91721 | Critical | Use-after-free | Internals |
| CVE-2026-91749 | Critical | Use-after-free | Workers |
| CVE-2026-91724 | High | Use-after-free | Input |
| CVE-2026-91728 | High | Integer overflow | V8 |
| CVE-2026-91734 | High | Incorrect authorization | Core |
| CVE-2026-91727 | High | Incorrect reference resolution | Extensions |
| CVE-2026-91743 | High | Race condition | Core |
| CVE-2026-91744 | High | Race condition | PlatformIntegration |
| CVE-2026-91712 | High | Race condition | Extensions |
| CVE-2026-91748 | High | Race condition | Extensions |
| CVE-2026-91720 | High | Uninitialized resource | ANGLE |
| CVE-2026-91731 | High | Type confusion | Compositing |
| CVE-2026-91747 | High | Use-after-free | Skia |
| CVE-2026-91733 | High | Improper state validation | Skia |
| CVE-2026-91741 | High | Type confusion | CacheStorage |
| CVE-2026-91709 | High | Type confusion | ServiceWorker |
| CVE-2026-91717 | High | Missing authorization | Android |
| CVE-2026-91735 | High | Incorrect authorization | WebUI |
| CVE-2026-91708 | High | Race condition | Network |
| CVE-2026-91736 | High | Use-after-free | DOM |
| CVE-2026-91740 | High | Uninitialized resource | Skia |
| CVE-2026-91710 | High | Use-after-free | WebAppInstalls |
| CVE-2026-91718 | High | Use-after-free | Core |
| CVE-2026-91716 | High | Use-after-free | Auth |
| CVE-2026-91746 | High | Integer overflow | Compositing |
| CVE-2026-91729 | High | Use-after-free | DigitalCredentials |
| CVE-2026-91737 | High | Use-after-free | |
| CVE-2026-91711 | High | Out-of-bounds write | ServiceWorker |
| CVE-2026-91715 | High | Type confusion | ServiceWorker |
| CVE-2026-91745 | High | Use-after-free | V8 |
| CVE-2026-91723 | Medium | Race condition | WebAppInstalls |
| CVE-2026-91732 | Medium | Missing authorization | AppManifest |
| CVE-2026-91742 | Medium | Confused deputy | PriceTracking |
| CVE-2026-91714 | Medium | Observable discrepancy | Fonts |
| CVE-2026-91725 | Medium | Observable discrepancy | CSS |
| CVE-2026-91739 | Medium | Missing authorization | Transactions Platform |
| CVE-2026-91713 | Medium | Missing authorization | Browser |
| CVE-2026-91738 | Medium | Improper input validation | ANGLE |
| CVE-2026-91730 | Medium | Incomplete cleanup | GetUserMedia |
| CVE-2026-91722 | Medium | Use-after-free | Input |
| CVE-2026-91719 | Low | Code injection | XML |
Detailed bug links may remain restricted until most users receive the fixes. Google may preserve restrictions longer when a vulnerability exists in a third-party library on which other, not-yet-patched projects depend, limiting attackers’ access to technical information during deployment.
Users should open Chrome’s menu and navigate to Help and then About Google Chrome, allow the update to install, and select Relaunch. Google says Chrome normally updates in the background, but a restart is required to apply a pending release.
Enterprise administrators should accelerate deployment, confirm the running version across managed endpoints and investigate devices held back by update policies or pending restarts.
Google supports centralized Chrome update management through Group Policy on eligible Windows devices, while administrators can review applied settings at chrome://policy. On Windows, policy controls apply only to domain-joined or MDM-managed devices, so unmanaged systems and rarely connected endpoints require separate checks.
Security teams should inventory duplicate installations and alternate channels, enforce an update deadline, and confirm that users have relaunched the browser. Merely enabling automatic updates does not prove that the patched binary is running across the entire fleet.
Google credits AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer and AFL with detecting many security bugs. Given the number and severity of the fixes, users should verify installation of Chrome 153.0.8010.47/.48 on Windows or macOS and 153.0.8010.47 on Linux rather than waiting for the staged rollout to finish.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…
Hackers are advertising a new “uncensored” artificial intelligence service called Luciferus, positioning it as a…