CVE-2026-76037: Google Chrome vulnerability
Published Aug 18, 2026
·Updated
Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Affected Software
1 affected component
Google Chrome<151.0.7922.169
Event History
Aug 18, 2026
CVE Published
via MITRE·08:31 PM
Data Sourced
via MITRE·08:31 PM
DescriptionWeakness
Frequently Asked Questions
1
Which systems are affected?
Windows systems running Google Chrome before version 151.0.7922.169 are affected. The issue is in CredentialProvider and is described as allowing code execution outside the Chrome sandbox.
2
What access does an attacker need?
An attacker needs local access and the ability to use a local program to exploit the issue. The provided information does not describe a remote or web-only attack path.
3
What should be done to remediate this issue?
Update Google Chrome to version 151.0.7922.169 or later. No workaround or mitigation is provided in the available information.