Description
Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-15
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw in the DigitalCredentials component of Google Chrome that allows an attacker to run arbitrary code outside the browser sandbox. When a crafted HTML page containing a malicious DigitalCredentials request is processed, the freed memory can be dereferenced, leading to execution of attacker‑supplied code. The flaw is categorized as CWE‑416 and also involves CWE‑825, indicating improper privilege management that allows the code to escape sandbox restrictions. This can result in full system compromise, loss of confidentiality and integrity for any user that’s tricked into opening the page.

Affected Systems

All releases of Google Chrome prior to version 153.0.8010.47 are affected. The vulnerability exists across all operating systems that support the Chromium engine, and it is specifically listed for Google:Chrome in the CNA product list.

Risk and Exploitability

The CVSS score of 9.6 marks this as a critical vulnerability. However, the EPSS score of <1% indicates that, in the wild, exploitation attempts are expected to be very rare. The vulnerability is not listed in CISA’s KEV catalog, and it requires a social‑engineering attack vector that involves a user visiting a maliciously crafted HTML page. Once executed, the attacker can run code with operating‑system privileges, bypassing browser isolation mechanisms.

Generated by OpenCVE AI on September 18, 2026 at 13:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.47 or later
  • Disable or remove the Digital Credentials feature if it is not needed for your workflow
  • Remain cautious of unsolicited or suspicious web pages that may contain malicious content

Generated by OpenCVE AI on September 18, 2026 at 13:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 17 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: Chromium: Arbitrary code execution via use-after-free in DigitalCredentials
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Critical


Wed, 16 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-17T03:55:57.841Z

Reserved: 2026-09-14T22:52:11.697Z

Link: CVE-2026-91729

cve-icon Vulnrichment

Updated: 2026-09-16T10:17:31.913Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T21:16:46.263

Modified: 2026-09-17T17:54:30.433

Link: CVE-2026-91729

cve-icon Redhat

Severity : Critical

Publid Date: 2026-09-15T20:41:33Z

Links: CVE-2026-91729 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T13:15:06Z

Weaknesses