ZeroHour

CVE-2026-87530

mass

Uncontrolled Search Path Element in Google Chrome CredentialProvider on Windows

CVSS 3.1
8.1 high
EPSS
<1%p3
Published
()
Modified
AI analysis

Google Chrome's CredentialProvider component on Windows resolves a local program through an uncontrolled search path (CWE-427), the classic pattern that enables DLL/binary search-order hijacking. A local attacker who can plant a malicious file in a directory consulted by that search path can cause Chrome's CredentialProvider to load it. Successful abuse yields arbitrary code execution outside the Chrome sandbox, effectively a local sandbox escape with high confidentiality, integrity, and availability impact on the host (CVSS 8.1, scope-changed). Only Chrome on Windows prior to 153.0.8010.36 is affected; Chrome on other platforms is not named in the advisory. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days, so no in-the-wild exploitation is currently known.

What to do: Update Chrome on Windows to 153.0.8010.36 or later and confirm the running version via chrome://version; because the flaw requires a local foothold, prioritize endpoint hygiene by restricting write permissions on directories in the DLL/binary search path used by Chrome's CredentialProvider and auditing any third-party credential providers. There are no workarounds beyond patching and limiting local code execution on endpoints.

Affected
Google Chrome (Windows)prior to 153.0.8010.36
Estimated exposure
masshundreds of millions of Chrome-on-Windows installations (Chrome holds roughly two-thirds of desktop browser share across billions of users, the majority on… — Estimated from Chrome's dominant desktop browser market share (~65%) and its multi-billion-user installed base, most of which runs on Windows; note exploitation additionally requires local access to the machine.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-427
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.