Junglewise Threat Intelligence

CVE-2026-91729: Google Chrome use-after-free in DigitalCredentials

CVE-2026-91729 · Severity: critical · CVSS 9.6 · Published 2026-09-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a use-after-free memory vulnerability in the DigitalCredentials component that allows attackers to execute arbitrary code outside the browser sandbox. An attacker can exploit this by tricking users into visiting a malicious webpage, potentially gaining full control of the affected system and bypassing Chrome's security protections.

Technical details

A use-after-free vulnerability exists in the DigitalCredentials component of Google Chrome prior to version 153.0.8010.47. The vulnerability is triggered when processing a crafted HTML page and requires user interaction (social engineering / visiting a malicious site). Successful exploitation allows an attacker to execute arbitrary code outside the Chrome sandbox boundary, effectively breaking the browser's security isolation and gaining direct system-level access. The Chromium project rated this as High severity, and a patch is available in Chrome 153.0.8010.47 and later.

Affected products

  • Google Chrome prior to 153.0.8010.47

Timeline

  • 2026-09-15: disclosed: CVE-2026-91729 published

References

Related threats