Description
Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-10-02
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A use‑after‑free vulnerability in the SVG parser of Google Chrome versions before 154.0.8037.97 permits a remote attacker to execute arbitrary code inside the browser sandbox through a specially crafted HTML page. This flaw, categorized as CWE‑416, enables attackers to run code with the limited permissions of the browser’s sandbox environment, potentially compromising the client system or user data if the sandbox is escaped.

Affected Systems

The bug affects Google Chrome across all platforms (Windows, macOS, Linux) for versions earlier than 154.0.8037.97. Users running any older build are vulnerable until they install a later release that includes the fix.

Risk and Exploitability

Although the CVSS score is not provided, the vulnerability is rated high in Chromium’s severity assessment. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, indicating no publicly known exploits. The attack vector is inferred to be a malicious web page that a user visits; the attacker can embed crafted SVG content within that page to trigger the use‑after‑free. Exploitation requires that the victim open the malicious page, meaning the risk is mitigated by user behavior and browser update status.

Generated by OpenCVE AI on October 2, 2026 at 17:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Chrome update (at least 154.0.8037.97).
  • Ensure all devices run the patched version by using enterprise update management tools.
  • If updating is delayed, limit exposure by restricting SVG rendering via a content security policy or by disabling the feature through Chrome flags.

Generated by OpenCVE AI on October 2, 2026 at 17:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 18:15:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome SVG Parser Enables Remote Code Execution

Fri, 02 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 02 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-02T16:07:55.875Z

Reserved: 2026-09-30T23:12:14.123Z

Link: CVE-2026-103622

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T16:16:43.290

Modified: 2026-10-02T17:47:56.067

Link: CVE-2026-103622

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T18:00:04Z

Weaknesses