Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
CVSS Details
- CVSS 3.1 Base Score: 8.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade chromium | Aug 23, 2026 | Aug 23, 2026 |
| Freebsd | — | Upgrade ungoogled-chromiumUpgrade chromium | Aug 21, 2026 | Aug 20, 2026 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Aug 19, 2026 | Aug 18, 2026 |
| Microsoft Edge | — | Update Microsoft Edge to the latest version | Aug 21, 2026 | Aug 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub