Описание
Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | code not present |
| esm-apps/noble | not-affected | code not present |
| esm-apps/resolute | not-affected | code not present |
| jammy | not-affected | code not present |
| noble | not-affected | code not present |
| resolute | not-affected | code not present |
| upstream | released |
Показывать по
EPSS
9.6 Critical
CVSS3
Связанные уязвимости
A flaw was found in DigitalCredentials within Chromium. A remote attacker could exploit a use-after-free vulnerability by leveraging social engineering to entice a user to visit a specially crafted HTML page. Successful exploitation would allow the attacker to execute arbitrary code outside of the browser's security sandbox.
Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in DigitalCredentials in Google Chrome prior to 153.0.8 ...
Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
EPSS
9.6 Critical
CVSS3