Description
Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-10-06
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution Inside Sandbox
Action: Immediate Patch
AI Analysis

Impact

The flaw is a use‑after‑free in Chrome’s HTML parser that allows an attacker to execute arbitrary code with the same privileges as the renderer process. The vulnerability is classified as CWE‑416 and has a CVSS score of 8.8. The exploit can be triggered by delivering a crafted HTML page to a user, resulting in code execution confined initially to the sandboxed environment.

Affected Systems

All Chrome releases prior to 155.0.8059.39 on desktop platforms are affected. The description indicates that the issue applies to the stable channel on Windows, macOS, and Linux, which is inferred from the mention of desktop platforms and the stable channel update in the advisory.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in CISA KEV, but the high CVSS indicates significant risk. Attackers can embed malicious content in emails, websites, or local files, requiring user interaction to load the crafted page. Once exploited, the attacker obtains sandboxed code execution, which could lead to privilege escalation if the sandbox is bypassed. No public exploit code is documented, but the threat remains serious for users of outdated Chrome.

Generated by OpenCVE AI on October 7, 2026 at 03:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 155.0.8059.39 or later
  • Enable automatic updates so future patches are applied without manual intervention
  • Until the update is installed, avoid opening untrusted HTML files or visiting unknown sites that may contain malicious content

Generated by OpenCVE AI on October 7, 2026 at 03:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 07 Oct 2026 04:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Parser Enables Sandbox Code Execution

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-07T03:55:40.569Z

Reserved: 2026-10-06T16:30:43.122Z

Link: CVE-2026-106193

cve-icon Vulnrichment

Updated: 2026-10-06T19:41:30.470Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:45.443

Modified: 2026-10-07T04:17:47.663

Link: CVE-2026-106193

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T06:15:12Z

Weaknesses