CVE-2026-87530
massUncontrolled Search Path Element in Google Chrome CredentialProvider on Windows
Google Chrome's CredentialProvider component on Windows resolves a local program through an uncontrolled search path (CWE-427), the classic pattern that enables DLL/binary search-order hijacking. A local attacker who can plant a malicious file in a directory consulted by that search path can cause Chrome's CredentialProvider to load it. Successful abuse yields arbitrary code execution outside the Chrome sandbox, effectively a local sandbox escape with high confidentiality, integrity, and availability impact on the host (CVSS 8.1, scope-changed). Only Chrome on Windows prior to 153.0.8010.36 is affected; Chrome on other platforms is not named in the advisory. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days, so no in-the-wild exploitation is currently known.
What to do: Update Chrome on Windows to 153.0.8010.36 or later and confirm the running version via chrome://version; because the flaw requires a local foothold, prioritize endpoint hygiene by restricting write permissions on directories in the DLL/binary search path used by Chrome's CredentialProvider and auditing any third-party credential providers. There are no workarounds beyond patching and limiting local code execution on endpoints.
| Google Chrome (Windows) | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-427
- Vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.