Impact
The vulnerability is a use‑after‑free in Chrome’s garbage collection that allows a remote attacker to execute arbitrary code inside the browser sandbox when a crafted HTML page is loaded. The flaw arises from untrusted input handling during memory reclamation, corresponding to CWE‑416. The impact can compromise confidentiality, integrity, or availability on the victim’s machine, as malicious code can run with sandboxed privileges.
Affected Systems
The issue affects Google Chrome desktop versions prior to 155.0.8059.39 on all operating systems. Users running older Chrome releases are vulnerable until they upgrade to the patched build released in October 2026.
Risk and Exploitability
The CVSS base score is 8.8, indicating a high‑severity risk. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog, so its exploitation likelihood is not quantified. Attackers would need to serve a malicious webpage that triggers the garbage‑collection exploit, requiring the victim to view the page; the code then executes inside the sandbox, representing a serious risk for users visiting compromised sites.
OpenCVE Enrichment