Description
Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-10-02
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A use‑after‑free flaw in the FedCM implementation of Google Chrome allows a remote attacker to execute arbitrary code outside the browser sandbox through a crafted HTML page. The vulnerability, rated high by Chromium, could compromise confidentiality, integrity, and availability of the affected system if an unprivileged web page triggers the exploit.

Affected Systems

Google Chrome users who have not upgraded to version 154.0.8037.97 or later are affected. The flaw exists in all prior releases of Chrome and can impact any user visiting a site that can deliver a malicious HTML payload to the browser.

Risk and Exploitability

The vulnerability carries a high severity rating by Chromium. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. However, the potential for remote code execution outside the sandbox underscores a significant risk if an attacker can deliver a crafted page to the user. The likely attack vector is a remotely hosted malicious website that triggers the use‑after‑free condition during FedCM processing.

Generated by OpenCVE AI on October 2, 2026 at 17:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 154.0.8037.97 or later.
  • If an upgrade cannot be performed immediately, disable the FedCM feature by launching Chrome with the flag --disable-features=FedCM or by setting the corresponding experimental flag to off through chrome://flags.
  • Avoid visiting untrusted websites that could supply malicious HTML and use a strict content‑security policy to limit script execution if possible.

Generated by OpenCVE AI on October 2, 2026 at 17:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 02 Oct 2026 18:15:00 +0000

Type Values Removed Values Added
Title Use after Free in FedCM Enables Remote Code Execution in Google Chrome

Fri, 02 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description Use after free in FedCM in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-02T16:07:54.904Z

Reserved: 2026-09-30T23:12:22.943Z

Link: CVE-2026-103630

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T16:16:44.150

Modified: 2026-10-02T17:47:56.067

Link: CVE-2026-103630

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T18:15:12Z

Weaknesses