Description
Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

This vulnerability is a use‑after‑free flaw in the font rendering component of Google Chrome on Windows. By loading a specially crafted HTML page, a remote attacker can trigger a memory access after the font object has been freed, allowing execution of arbitrary code inside Chrome’s sandbox. The flaw carries a CVSS score of 8.8, indicating high severity, and the Chromium team classifies it as a medium‑severity security issue. The impact is that an attacker could run code with sandboxed privileges, potentially elevating privileges or exfiltrating data if further vulnerabilities are leveraged.

Affected Systems

The flaw affects Google Chrome running on Windows systems with versions earlier than 155.0.8059.39. Only desktop builds of the stable channel are impacted according to the release notes. The vulnerability is specific to the font rendering engine in those Chrome releases.

Risk and Exploitability

The CVSS score of 8.8 places this bug in the high‑risk range, and the lack of an EPSS score means its current exploitation probability is uncertain. The flaw is listed as not being part of the CISA KEV catalog. Attackers could exploit the vulnerability by serving a malicious web page to a victim who has Chrome installed and is willing to view it, thereby triggering the use‑after‑free during font processing. Given that the flaw requires crafted page delivery and that normal browser updates will fix it, the risk is mitigated by applying the patch promptly.

Generated by OpenCVE AI on October 6, 2026 at 22:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 155.0.8059.39 or later, which contains the memory‑sanitization fix for the font rendering component.
  • Ensure that Chrome’s auto‑update feature is enabled so future critical patches are applied automatically.
  • If an immediate update is impractical, restrict web browsing to safe sites and disable custom font usage via policy or in‑browser settings while awaiting a patch.

Generated by OpenCVE AI on October 6, 2026 at 22:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 22:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Font Rendering Allowing Remote Code Execution

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-416
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T19:15:23.064Z

Reserved: 2026-10-06T16:36:52.726Z

Link: CVE-2026-106373

cve-icon Vulnrichment

Updated: 2026-10-06T19:05:50.323Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:06.413

Modified: 2026-10-06T20:17:24.463

Link: CVE-2026-106373

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T22:15:06Z

Weaknesses