Impact
The V8 JavaScript engine in Google Chrome contains a use‑after‑free bug that allows a remote attacker to execute arbitrary code within the browser sandbox by delivering a crafted HTML page. The vulnerability relies on freeing an object and then accessing it again, which can be triggered when the page is rendered, giving attackers the ability to run code that would normally be restricted by the sandbox.
Affected Systems
Affected systems are Google Chrome browsers on any operating system that are running versions older than 155.0.8059.39. The fix is included in the stable‑channel release of Chrome that was made available in October 2026.
Risk and Exploitability
The CVSS score of 8.8 signals a high‑severity flaw, and while the EPSS score is not available, the fact that the vulnerability can be triggered by a malicious web page means it is potentially exploitable by remote actors. It is not listed in the CISA KEV catalog, but the impact of arbitrary code execution demands that users update the browser as soon as possible.
OpenCVE Enrichment