External risk intelligence

Google Chrome Use After Free in Authentication Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-91716

The vulnerability affects a web browser, which is a client-side application designed to render internet-hosted content. While it is a client application, it is frequently used to interact with public-facing web pages and services, making it a primary target for remote, internet-based attacks via crafted HTML content.

Use After Free

Google Chrome

before 153.0.8010.47

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This CVE involves a critical vulnerability found in Google Chrome. A security flaw related to memory management could allow a remote attacker to execute malicious code on a user's system by tricking them into visiting a specially crafted webpage. While the specific impact depends on the user's browsing habits and system configuration, this type of vulnerability presents a potential risk to user data and system integrity.

  • Flaw lets attackers run code on users' computers.
  • High severity; affects widely used web browser.
  • Confirm if Chrome is updated; assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by tricking a user into visiting a malicious HTML page. This page would contain specially crafted content designed to trigger a use-after-free flaw within Chrome's authentication process. If successful, the attacker could potentially execute arbitrary code on the user's system, even escaping the browser's sandbox.

  • No authentication or privileges required.
  • Triggered by visiting a malicious HTML page.
  • Risk of arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A use-after-free vulnerability in Chrome's authentication component could allow an attacker to execute arbitrary code outside the browser's sandbox when a user visits a malicious HTML page. This could affect the user's system and any data it stores.

  • Arbitrary code execution.
  • Malicious HTML page interaction.
  • Compromised system and data.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Google Chrome's authentication component requires immediate attention from teams responsible for endpoint security and application oversight. The first step is to inventory all Chrome installations, verify exposure to the internet, and identify business-critical systems or users running affected versions. Subsequently, coordinate with the relevant application or platform owners to plan and implement the necessary updates.

  • Identify responsible application or platform owners.
  • Verify browser reachability and business criticality.
  • Plan and coordinate Chrome browser updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Chrome in the context of this vulnerability?

Google Chrome is a widely used web browser based on the Chromium project. It acts as an interface between your computer and the internet, processing complex web content like HTML, CSS, and JavaScript. This CVE specifically affects the authentication component within the browser, which is responsible for managing user credentials and session security when you navigate to websites.

What does use-after-free mean for CVE-2026-91716?

This is a memory management weakness, classified as CWE-416. It occurs when software continues to use a memory location after it has been cleared or released. In this CVE, an attacker can manipulate this flaw to replace that freed memory with their own malicious code, effectively tricking the browser into executing instructions that were not intended by the developers.

How is this Chrome vulnerability triggered?

The vulnerability is triggered when a user visits a specifically crafted malicious HTML page. It does not occur through standard, legitimate web browsing or by simply having the browser installed. The attacker relies on the user interacting with the compromised content, which then activates the flawed logic within the browser's authentication process.

Why is this CVE concerning for internet-facing systems?

According to Halo Surface Signal, because Chrome is a client-side application designed to render internet-hosted content, it is frequently used to visit public-facing sites. This makes it a primary target for remote attacks. Even though the browser is client-side, its constant interaction with the open web creates a direct path for attackers to deliver the malicious HTML required to exploit the browser.

Do I need to update my Chrome browser?

Yes. If your current version is earlier than 153.0.8010.47, your software contains this vulnerability. You should prioritize updating your browser to the latest stable version provided by Google. Verifying your current version number and applying the update is the standard way to resolve the flaw and ensure the authentication component is patched.

References