Description
Use after free in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Published: 2026-09-29
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch
AI Analysis

Impact

The vulnerability is a use-after-free flaw in the Metrics component of Google Chrome, classified as CWE-416. It allows a remote attacker to craft network traffic that triggers a use-after-free condition, enabling the execution of arbitrary code outside the browser sandbox. The impact is the compromise of the host system’s confidentiality, integrity, and availability, as the attacker can run code with kernel or system-level privileges if exploitation succeeds.

Affected Systems

Google Chrome version 154.0.8037.57 and earlier across all supported operating systems. The flaw affects any machine running those versions of Chrome and listening for external network traffic that can be crafted to target the vulnerable component.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation at the time of this analysis. The likely attack vector is a remote attacker sending specially crafted traffic to a victim’s Chrome instance, potentially leveraging the browser’s ability to request network resources, such as HTTPS or HTTP requests, or WebSocket connections. While the precise exploitation conditions are not fully disclosed, the description indicates that arbitrary code execution outside the sandbox is possible.

Generated by OpenCVE AI on September 29, 2026 at 23:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 154.0.8037.57 or later
  • If an immediate update is not feasible, disable the Metrics component by turning off telemetry via Chrome policies or flags (e.g., set MetricsReportingEnabled to false)
  • Restrict network traffic to the metrics collection endpoints by updating firewall rules or proxy settings to block or monitor suspicious traffic patterns

Generated by OpenCVE AI on September 29, 2026 at 23:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6513-1 chromium security update
History

Wed, 30 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title Use-after-free in Chrome Metrics Enables Remote Code Execution chromium-browser: chromium-browser: Use after free in Metrics
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Important


Wed, 30 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Use-after-free in Chrome Metrics Enables Remote Code Execution

Tue, 29 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 29 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Use after free in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-30T03:57:17.352Z

Reserved: 2026-09-22T05:09:21.571Z

Link: CVE-2026-95333

cve-icon Vulnrichment

Updated: 2026-09-29T20:37:39.631Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:25.797

Modified: 2026-09-30T04:18:45.023

Link: CVE-2026-95333

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-29T17:31:55Z

Links: CVE-2026-95333 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T23:45:17Z

Weaknesses