Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91729

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 9.6
EPSS Низкий

Описание

A flaw was found in DigitalCredentials within Chromium. A remote attacker could exploit a use-after-free vulnerability by leveraging social engineering to entice a user to visit a specially crafted HTML page. Successful exploitation would allow the attacker to execute arbitrary code outside of the browser's security sandbox.

Ссылки на источники

Дополнительная информация

Статус:

Critical
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2534421chromium-browser: Chromium: Arbitrary code execution via use-after-free in DigitalCredentials

EPSS

Процентиль: 16%
0.00246
Низкий

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
2 дня назад

Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.6
nvd
3 дня назад

Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.6
debian
3 дня назад

Use after free in DigitalCredentials in Google Chrome prior to 153.0.8 ...

CVSS3: 9.6
github
3 дня назад

Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 16%
0.00246
Низкий

9.6 Critical

CVSS3