Description
Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free in Chrome’s garbage collection that allows a remote attacker to execute arbitrary code inside the browser sandbox when a crafted HTML page is loaded. The flaw arises from untrusted input handling during memory reclamation, corresponding to CWE‑416. The impact can compromise confidentiality, integrity, or availability on the victim’s machine, as malicious code can run with sandboxed privileges.

Affected Systems

The issue affects Google Chrome desktop versions prior to 155.0.8059.39 on all operating systems. Users running older Chrome releases are vulnerable until they upgrade to the patched build released in October 2026.

Risk and Exploitability

The CVSS base score is 8.8, indicating a high‑severity risk. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog, so its exploitation likelihood is not quantified. Attackers would need to serve a malicious webpage that triggers the garbage‑collection exploit, requiring the victim to view the page; the code then executes inside the sandbox, representing a serious risk for users visiting compromised sites.

Generated by OpenCVE AI on October 7, 2026 at 02:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 155.0.8059.39 or later.
  • If an immediate update is not possible, disable JavaScript or use a content‑blocking extension for sites that are untrusted, noting that this may impair browser functionality.
  • Continuously monitor Google’s security advisories and apply future patches as they become available.

Generated by OpenCVE AI on October 7, 2026 at 02:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 02:30:00 +0000

Type Values Removed Values Added
Title Chrome Garbage Collection Use-After-Free Enables Remote Code Execution

Wed, 07 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-07T03:55:25.669Z

Reserved: 2026-10-06T16:34:25.862Z

Link: CVE-2026-106291

cve-icon Vulnrichment

Updated: 2026-10-06T19:05:51.887Z

cve-icon NVD

Status : Analyzed

Published: 2026-10-06T19:17:56.940

Modified: 2026-10-07T13:43:38.223

Link: CVE-2026-106291

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T02:15:10Z

Weaknesses