Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91722

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 9.6
EPSS Низкий

Описание

Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

A flaw was found in Google Chrome. This 'use after free' vulnerability occurs when the program attempts to use memory that has been deallocated, leading to unpredictable behavior. A remote attacker could exploit this by tricking a user into visiting a specially crafted HTML page. Successful exploitation could allow the attacker to execute arbitrary code outside of the browser's security sandbox, potentially gaining control over the affected system.

Ссылки на источники

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2534432chromium-browser: Google Chrome: Arbitrary Code Execution via Use-After-Free Vulnerability

EPSS

Процентиль: 15%
0.00235
Низкий

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
2 дня назад

Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
nvd
3 дня назад

Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 8.8
debian
3 дня назад

Use after free in Input in Google Chrome prior to 153.0.8010.47 allowe ...

CVSS3: 8.8
github
3 дня назад

Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

EPSS

Процентиль: 15%
0.00235
Низкий

9.6 Critical

CVSS3