CVE-2026-91729
Google · Chrome
A use after free vulnerability in the Google Chrome DigitalCredentials component allows a remote attacker to execute arbitrary code via a crafted HTML page.
Executive summary
A critical use after free vulnerability in Google Chrome, identified as CVE-2026-91729, enables remote code execution and requires immediate patching to prevent system compromise.
Vulnerability
This flaw is a use after free vulnerability within the DigitalCredentials component. An unauthenticated remote attacker can trigger this vulnerability by using social engineering to lure a user into visiting a crafted HTML page, leading to arbitrary code execution outside the browser sandbox.
Business impact
Successful exploitation of this vulnerability results in full system compromise, as the attacker can execute code with the privileges of the logged in user outside the standard browser sandbox. Given the CVSS score of 9.6, this represents a critical risk to business operations, including potential data exfiltration, ransomware deployment, or unauthorized lateral movement within the network.
Remediation
Immediate Action: Update Google Chrome to version 153.0.8010.47 or later immediately across all managed endpoints to resolve the underlying memory management flaw.
Proactive Monitoring: Monitor browser-related security logs for unusual process execution patterns or unexpected child processes originating from the Chrome browser application.
Compensating Controls: Ensure that endpoint protection solutions are configured to detect and block malicious code execution attempts, and utilize browser policies to restrict the execution of untrusted or suspicious scripts.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit available.
Analyst recommendation
The severity of this vulnerability, combined with the potential for sandbox escape, necessitates an urgent organizational response. IT administrators should prioritize the deployment of the browser update to all workstations and servers to mitigate the risk of remote code execution. Failure to patch these systems leaves the organization vulnerable to sophisticated browser based attacks.
More Google CVEs all →
History
CVE Brief tracked this CVE 4 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.6 (3.1)
- Analyst report written