Описание
Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
A flaw was found in Google Chrome. A local attacker could exploit a link following vulnerability within the CredentialProvider component. This vulnerability allows for the execution of arbitrary code outside the browser's security sandbox through a local program.
Отчет
This vulnerability affects Chromium-based browsers and applications utilizing QtWebEngine in Red Hat Community Projects. A local attacker could exploit a link following flaw within the CredentialProvider component, leading to arbitrary code execution outside the browser's sandbox. Exploitation requires user interaction, such as clicking a malicious link.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Дополнительная информация
Статус:
8.2 High
CVSS3
Связанные уязвимости
Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Link following in CredentialProvider in Google Chrome on on Windows pr ...
Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
8.2 High
CVSS3