Description
Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-10-06
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

This vulnerability is a use‑after‑free flaw in Chrome’s Tint layer rendering code. The flaw can be triggered by a carefully crafted HTML page and allows a remote attacker who can cause the page to be processed to potentially execute arbitrary code outside the Chrome sandbox. The issue is marked as high severity by the Chromium security team because it undermines the basic isolation that the browser enforces for third‑party content.

Affected Systems

Google Chrome is affected. The flaw exists in all releases prior to Chrome 155.0.8059.39, including stable, beta, and dev channels before that version. Users running earlier releases are at risk until they upgrade to the patched version.

Risk and Exploitability

The CVSS score of 9.6 highlights a high impact. EPSS data is not available for this CVE, and it has not been added to the CISA KEV catalog. Because the flaw is triggered by an external HTML page, the attack vector is remote and does not require local privileges. A successful exploitation would give the attacker code‑execution rights with the same privileges as the Chrome process, potentially bypassing the sandbox. The lack of a published workaround means that the only known defense is to apply the vendor update before engaging with untrusted content.

Generated by OpenCVE AI on October 7, 2026 at 02:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 155.0.8059.39 or newer.
  • Confirm that Chrome’s sandboxing is enabled and not overridden by custom launch flags or policies.
  • Avoid rendering or loading untrusted HTML content that could trigger the Tint layer rendering, such as by filtering or sanitizing user‑supplied pages.

Generated by OpenCVE AI on October 7, 2026 at 02:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 06:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 07 Oct 2026 03:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Tint Layer Enables Remote Code Execution via Crafted HTML

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-07T03:55:33.590Z

Reserved: 2026-10-06T16:34:15.655Z

Link: CVE-2026-106281

cve-icon Vulnrichment

Updated: 2026-10-06T19:26:44.762Z

cve-icon NVD

Status : Analyzed

Published: 2026-10-06T19:17:55.827

Modified: 2026-10-07T13:44:17.820

Link: CVE-2026-106281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T05:45:12Z

Weaknesses