Executive brief
Google Chrome contains a use-after-free memory vulnerability in the DigitalCredentials component that allows attackers to execute arbitrary code outside the browser sandbox. An attacker can exploit this by tricking users into visiting a malicious webpage, potentially gaining full control of the affected system and bypassing Chrome's security protections.
Technical details
A use-after-free vulnerability exists in the DigitalCredentials component of Google Chrome prior to version 153.0.8010.47. The vulnerability is triggered when processing a crafted HTML page and requires user interaction (social engineering / visiting a malicious site). Successful exploitation allows an attacker to execute arbitrary code outside the Chrome sandbox boundary, effectively breaking the browser's security isolation and gaining direct system-level access. The Chromium project rated this as High severity, and a patch is available in Chrome 153.0.8010.47 and later.
Affected products
- Google Chrome prior to 153.0.8010.47
Timeline
- 2026-09-15: disclosed: CVE-2026-91729 published