Description
Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch
AI Analysis

Impact

A use‑after‑free flaw in the Media component of Google Chrome allows a remote attacker to trigger arbitrary code execution inside the browser’s sandbox by loading a specifically crafted HTML page. The vulnerability originates from unsafe handling of freed memory in media processing, enabling the attacker to inject executable code that runs with the privileges of the sandboxed process.

Affected Systems

Google Chrome versions prior to 155.0.8059.39 are affected on all supported platforms. The flaw was present in the stable channel at the time of the advisory and affects any instance of the browser that processes media content from web pages.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, through a malicious web page that a user visits. Successful exploitation would allow code execution inside the browser sandbox, which could be used for privilege escalation or lateral movement if exploited in conjunction with other weaknesses.

Generated by OpenCVE AI on October 7, 2026 at 02:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Chrome version (155.0.8059.39 or later) to remove the use‑after‑free flaw.
  • Enable Chrome’s automatic update feature to ensure future patches are applied promptly.
  • Use browser extensions or host‑based content filtering to block or limit media loading from untrusted sources, reducing the chance of exploitation.

Generated by OpenCVE AI on October 7, 2026 at 02:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-07T03:55:24.963Z

Reserved: 2026-10-06T16:35:39.792Z

Link: CVE-2026-106335

cve-icon Vulnrichment

Updated: 2026-10-06T19:05:50.997Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:01.910

Modified: 2026-10-07T04:18:02.470

Link: CVE-2026-106335

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T05:00:11Z

Weaknesses