Executive brief
Google Chrome's credential provider on Windows contains a path traversal vulnerability that allows a local attacker to execute arbitrary code outside the browser sandbox. An attacker with local access to the system can exploit this flaw through a specially crafted local program, potentially compromising the entire system and enabling further attacks or data theft.
Technical details
An uncontrolled search path element vulnerability exists in Chrome's CredentialProvider component on Windows. The vulnerability allows a local attacker to execute arbitrary code by manipulating the search path used by the credential provider when loading executables, bypassing the browser's sandbox isolation. The attack requires local access to the system and can be triggered via a malicious local program; no user interaction or authentication is required. Exploitation results in arbitrary code execution outside the Chrome sandbox with the privileges of the affected user. This vulnerability is patched in Chrome 153.0.8010.36 and later versions.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched