External risk intelligence

Chrome DigitalCredentials Use After Free Allows Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-91729

This vulnerability exists within a web browser client. Exploitation requires a user to navigate to a specifically crafted HTML page via social engineering, rather than the browser being a public-facing service or infrastructure component that is reachable by remote attackers without user interaction.

Use After Free

Google Chrome

before 153.0.8010.47

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the DigitalCredentials component of Chrome, prior to a recent update, could allow attackers to execute malicious code by luring users to a compromised webpage. This type of flaw, while requiring user interaction, presents a potential risk if widespread.

  • Browser flaw allows code execution.
  • Requires tricking users to visit a bad site.
  • Confirm if users are using the latest browser version.

Attack Path

How an attacker could exploit the issue

An attacker could trick a user into visiting a malicious webpage. This page would contain specially crafted HTML designed to trigger a use-after-free vulnerability within Chrome's DigitalCredentials feature. If successful, this could allow the attacker to execute code on the user's system, bypassing security boundaries.

  • No authentication or privileges needed.
  • Visiting a malicious webpage triggers the flaw.
  • Risk of arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A use-after-free vulnerability in Google Chrome's DigitalCredentials component could allow a remote attacker, through social engineering, to execute arbitrary code outside the browser's sandbox when a user visits a malicious HTML page.

  • Arbitrary code execution.
  • User visits crafted HTML page.
  • Compromise of user's device.

Operational Fix

Recommended remediation, mitigation, and detection steps

Addressing this critical vulnerability in Google Chrome requires coordination between end-user support, platform teams managing desktop environments, and potentially vendor management if a managed service is involved. The first actionable step is to identify all Chrome installations, confirm their exposure, and determine the business criticality of affected systems before planning remediation.

  • Ownership: End-user support and platform teams.
  • Verify first: Chrome installations and reachability.
  • Action: Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Chrome's DigitalCredentials component?

DigitalCredentials is a feature within Google Chrome designed to handle the secure exchange and verification of identity-related information during web browsing. It acts as a bridge between the browser and websites requesting user authentication or identity proofs, ensuring this sensitive data is processed within the browser's architecture.

How does a use-after-free vulnerability work in CVE-2026-91729?

This flaw belongs to the Use After Free (CWE-416) class. It occurs when a program continues to use a pointer to a memory location after that memory has been cleared or freed. In this specific case, an attacker can manipulate this memory error to corrupt browser operations and potentially execute unauthorized code on the host system.

Does simply opening Chrome trigger CVE-2026-91729?

No. The vulnerability does not trigger through standard browser use or by simply having the application open. It requires a specific precondition where a user is tricked via social engineering into navigating to a malicious HTML page specifically designed to exploit the flaw.

Is my system at high risk according to Halo Surface Signal?

Halo Surface Signal assesses the risk as very unlikely. Because this is a client-side browser vulnerability requiring user interaction through social engineering, it does not act like a public-facing service or infrastructure component that an attacker can reach and compromise autonomously over the network.

How can I protect systems from this Chrome vulnerability?

Your primary step is to ensure all Chrome installations are updated to at least version 153.0.8010.47 or later. Coordinate with your IT or platform management teams to verify that your current browser versions are no longer within the affected range, effectively closing the memory management gap.

References