Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91718

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 9.6
EPSS Низкий

Описание

Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Google Chrome. A remote attacker could exploit a use-after-free vulnerability in the Core component by enticing a user to visit a specially crafted HTML page. This could lead to arbitrary code execution outside of the browser's sandbox, potentially compromising the affected system.

Ссылки на источники

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2534472chromium-browser: Google Chrome: Arbitrary code execution via use-after-free vulnerability

EPSS

Процентиль: 15%
0.00235
Низкий

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
2 дня назад

Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.6
nvd
3 дня назад

Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.6
debian
3 дня назад

Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed ...

CVSS3: 9.6
github
3 дня назад

Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 15%
0.00235
Низкий

9.6 Critical

CVSS3