CVE-2026-91721
CVSS 8.8 HIGH: use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. EPSS 0.3% (27th percentile).
Vulnerabilities & Exploits
Google and Mozilla shipped fresh browser security updates: Chrome 153 fixes 42 vulnerabilities, including three critical bugs, and Firefox 156 fixes 73. Google’s builds are 153.0.8010.47/.48 on Windows and macOS and 153.0.8010.47 on Linux; Mozilla says the larger Firefox count partly reflects a change in how it lists memory-safety bugs.
In Chrome, the critical issues include an out-of-bounds read in WebGL and two use-after-free bugs in Internals and Workers. Firefox’s patch set includes use-after-free, privilege-escalation, sandbox-escape, site-isolation, and mitigation-bypass flaws, so the practical effect is the same for both browsers: vulnerable clients stay exposed until the new builds land.
For managed fleets, the operational signal is simple. Chrome’s three critical CVEs and Firefox’s 73 fixes are rolling out now, but Firefox’s raw CVE total is not a clean severity comparison with older advisories. The exposure that matters is whether browser updates are fully deployed across Windows, macOS, and Linux endpoints.
2 sources · 13h ago
CVSS 8.8 HIGH: use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. EPSS 0.3% (27th percentile).
CVSS 9.6 CRITICAL: use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. EPSS 0.3% (27th percentile).
CVSS 4.7 MEDIUM: out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. EPSS 0.2% (15th percentile).
SecurityWeek
Chrome, Firefox Updates Patch 115 Vulnerabilities
Google resolved 42 security defects in Chrome, and Mozilla fixed 73 bugs in Firefox.
originalCSIRT Italia / ACN
Risolte vulnerabilità in Google Chrome
Google ha rilasciato un aggiornamento per il browser Chrome al fine di correggere 42 nuove vulnerabilità di sicurezza, di cui 3 con gravità “critica” e 28 con gravità “alta”.
originalPart of the PlainSec briefing for 2026-09-16
Every edition of this story: Chrome and Firefox Ship Large Security Batches