External risk intelligence

Chrome Workers Use After Free Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-91749

This vulnerability is located in the Google Chrome browser and requires a user to navigate to a crafted HTML page. As a client-side application, it is not an internet-facing service, gateway, or management interface that listens for unsolicited public network connections. It is categorized as a client-side vulnerability rather than a server-side attack surface.

Use After Free

Google Chrome

before 153.0.8010.47

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A use-after-free vulnerability in Google Chrome's Workers feature could allow an attacker to execute code outside the browser's sandbox by tricking a user into visiting a malicious website.

  • Browser code flaw allows unauthorized execution.
  • Attackers can exploit user browsing habits.
  • Confirm relevance and ensure user protection.

Attack Path

How an attacker could exploit the issue

An attacker could trick a user into visiting a malicious web page, which then triggers a use-after-free vulnerability within Chrome's Workers. This could allow the attacker to execute code on the user's system, potentially bypassing security restrictions.

  • Requires user interaction with a malicious page.
  • Triggered by a use-after-free flaw.
  • Risk of arbitrary code execution outside sandbox.

Live Threat

Current exploitation, exposure, and threat context

A use-after-free vulnerability in Google Chrome's Workers component could allow a remote attacker to execute arbitrary code outside the browser's sandbox when a user visits a specially crafted HTML page. This could potentially impact the confidentiality, integrity, and availability of the user's system.

  • Arbitrary code execution on user's system.
  • User visits a malicious HTML page.
  • Compromised system with potential data loss.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Google Chrome affects client-side applications and requires user interaction with a malicious HTML page. The first practical step is to identify all instances of the affected Chrome version within your environment, determine their business criticality, and then engage the appropriate teams for remediation planning.

  • Chrome owners are responsible for remediation.
  • Verify user exposure and criticality first.
  • Plan updates during maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Chrome and how do Workers function?

Google Chrome is a web browser used for accessing online content, while Workers are a background processing feature that enables scripts to run independently of the main browser thread. They help improve performance for complex tasks like data processing, but this architecture creates a unique space in memory that can be vulnerable if not managed correctly.

What is a use-after-free vulnerability in CVE-2026-91749?

This vulnerability, classified as CWE-416, occurs when a program continues to use a pointer after the memory it references has been cleared or freed. In the context of CVE-2026-91749, this flaw allows an attacker to manipulate memory, potentially gaining the ability to run unauthorized code by forcing the browser to perform unexpected actions.

How is this Chrome vulnerability triggered?

An attacker must trick a user into visiting a specially crafted HTML page to initiate the exploit. Simply having the browser installed or running benign sites does not trigger the bug; the malicious code specifically exploits the interaction between the website's content and the browser's background Workers component.

Is my system at risk if I use Chrome internally?

Halo Surface Signal notes that since Chrome is a client-side application rather than an internet-facing server or gateway, it does not listen for unsolicited public network connections. However, because this vulnerability relies on user navigation, any device used to browse the web is potentially at risk regardless of whether it resides in an internal or external network zone.

Do I need to update my Chrome browser to fix this?

Yes, updating is the primary defense. Start by auditing your environment to locate all systems running Chrome versions older than 153.0.8010.47. Once you identify these instances, prioritize them for updates through your standard maintenance processes to ensure the browser's security sandbox and memory management protections are restored.

References