CVE-2026-76037: Link following in CredentialProvider
Chromium: CVE-2026-76037 Link following in CredentialProvider
Other sources
Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.7922.169 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.4129.101 - Upgrade
Upgrade
Chromium/Google Chrome (Windows)to a version that resolves this vulnerability.Fixed in 151.0.7922.169 - Compensating control
On Microsoft Edge (Chromium-based), update Edge since it ingests Chromium and addresses the Chromium CVE.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
Which systems are affected?
Windows systems running Google Chrome before version 151.0.7922.169 are affected. The issue is in CredentialProvider and is described as allowing code execution outside the Chrome sandbox.
What access does an attacker need?
An attacker needs local access and the ability to use a local program to exploit the issue. The provided information does not describe a remote or web-only attack path.
What should be done to remediate this issue?
Update Google Chrome to version 151.0.7922.169 or later. No workaround or mitigation is provided in the available information.