Description
Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Use after free in the Streaming component of Google Chrome allows a remote attacker who tricks a user into opening a crafted HTML page to potentially execute arbitrary code inside the sandbox, enabling compromise of the user’s browser session.

Affected Systems

The affected product is Google Chrome; vulnerabilities exist in all pre‑155.0.8059.39 builds on desktop platforms.

Risk and Exploitability

The vulnerability has a CVSS score of 8.8, indicating high severity. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog, suggesting a moderate likelihood of exploitation in the wild. Attackers would need to deliver a malicious HTML payload, most likely via social engineering, to trigger the use after free condition and achieve remote code execution within the browser sandbox.

Generated by OpenCVE AI on October 7, 2026 at 02:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Chrome to version 155.0.8059.39 or later to apply the vendor‑supplied fix for the use‑after‑free error.
  • If immediate update is not possible, block access to streaming content from untrusted origins or disable the streaming feature in Chrome’s settings to mitigate the use‑after‑free path.
  • Employ network‑level controls or web‑security filters to detect and block malicious HTML or JavaScript content that could exploit the vulnerability.

Generated by OpenCVE AI on October 7, 2026 at 02:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 02:30:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome Streaming Enables Remote Execution

Wed, 07 Oct 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-07T03:55:26.342Z

Reserved: 2026-10-06T16:34:17.511Z

Link: CVE-2026-106283

cve-icon Vulnrichment

Updated: 2026-10-06T19:05:52.576Z

cve-icon NVD

Status : Analyzed

Published: 2026-10-06T19:17:56.047

Modified: 2026-10-07T13:43:53.113

Link: CVE-2026-106283

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T02:15:10Z

Weaknesses