Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91716

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 9.6

Описание

Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Google Chrome. This vulnerability, known as a use-after-free, occurs in the Auth component. A remote attacker could exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation could lead to arbitrary code execution outside of the browser's security sandbox, allowing the attacker to run malicious code on the affected system.

Ссылки на источники

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2534409chromium-browser: Google Chrome: Arbitrary code execution due to use after free vulnerability in Auth

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
2 дня назад

Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.6
nvd
4 дня назад

Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.6
debian
4 дня назад

Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed ...

CVSS3: 9.6
github
3 дня назад

Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

9.6 Critical

CVSS3