Description
Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-10-06
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch
AI Analysis

Impact

A use‑after‑free vulnerability in Google Chrome’s Tabs component on macOS prior to version 155.0.8059.39 allows a remote attacker to craft an HTML page that can trigger a use after free, potentially letting the attacker execute code outside the browser sandbox. The flaw is a classic memory corruption bug (CWE‑416) that may compromise confidentiality, integrity, and availability of the compromised system if executed. The vulnerability is considered high severity in Chromium’s internal ranking.

Affected Systems

Google Chrome running on macOS users with versions earlier than 155.0.8059.39 are affected. Any user who visits a maliciously crafted web page while Chrome is running is potentially exposed.

Risk and Exploitability

The attack vector is remote: a malicious web page triggers the use‑after‑free. The CVSS score of 9.6 indicates a critical level of risk, and the vulnerability is not listed in the CISA KEV catalog. The potential for exploitation is significant. No specific exploitation example is provided, but the flaw allows arbitrary code execution outside the sandbox, making it a high‑risk issue for affected users.

Generated by OpenCVE AI on October 7, 2026 at 02:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 155.0.8059.39 or later immediately to remove the use‑after‑free flaw.
  • Activate Chrome’s Site Isolation and sandboxing features to reduce the impact of any future memory corruption.
  • Configure Chrome’s security settings to block mixed or insecure content, and be cautious when visiting unfamiliar sites until a patch is applied.

Generated by OpenCVE AI on October 7, 2026 at 02:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 07 Oct 2026 03:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Tabs Enables Remote Code Execution on macOS

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-07T03:56:05.829Z

Reserved: 2026-10-06T16:34:36.749Z

Link: CVE-2026-106298

cve-icon Vulnrichment

Updated: 2026-10-06T19:26:44.040Z

cve-icon NVD

Status : Analyzed

Published: 2026-10-06T19:17:57.807

Modified: 2026-10-07T13:43:11.887

Link: CVE-2026-106298

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T05:15:12Z

Weaknesses