Description
Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-10-06
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The V8 JavaScript engine in Google Chrome contains a use‑after‑free bug that allows a remote attacker to execute arbitrary code within the browser sandbox by delivering a crafted HTML page. The vulnerability relies on freeing an object and then accessing it again, which can be triggered when the page is rendered, giving attackers the ability to run code that would normally be restricted by the sandbox.

Affected Systems

Affected systems are Google Chrome browsers on any operating system that are running versions older than 155.0.8059.39. The fix is included in the stable‑channel release of Chrome that was made available in October 2026.

Risk and Exploitability

The CVSS score of 8.8 signals a high‑severity flaw, and while the EPSS score is not available, the fact that the vulnerability can be triggered by a malicious web page means it is potentially exploitable by remote actors. It is not listed in the CISA KEV catalog, but the impact of arbitrary code execution demands that users update the browser as soon as possible.

Generated by OpenCVE AI on October 7, 2026 at 02:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Chrome version 155.0.8059.39 or later
  • Restart the browser so the new binaries are loaded
  • Monitor for anomalous behavior or attempts to load malicious HTML content

Generated by OpenCVE AI on October 7, 2026 at 02:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 07 Oct 2026 03:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome V8 Enables Remote Code Execution via Malicious Web Page

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-07T03:55:57.827Z

Reserved: 2026-10-06T16:36:11.308Z

Link: CVE-2026-106349

cve-icon Vulnrichment

Updated: 2026-10-06T19:40:56.870Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:03.523

Modified: 2026-10-07T04:18:03.870

Link: CVE-2026-106349

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T05:15:12Z

Weaknesses