Sceawere
Vulnerability Detail
CVE-2026-106234UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Use-After-Free in Chrome Network
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.6
- Creation Date
- 6h ago
- Vendor
- Product
- Chrome
- Attack Type
- Use after free
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.6",
"pubDate": "2026-10-06T19:17:50.250Z",
"pubdate": "2026-10-06T19:17:50.250Z",
"executiveSummary": "A Use-After-Free (UAF) vulnerability exists within the Network component of Google Chrome prior to version 155.0.8059.39.\nThis memory corruption flaw allows a remote attacker to achieve arbitrary code execution beyond the confines of the browser sandbox.\nThe vulnerability is classified as Low severity by Chromium, primarily due to the specific exploitation requirements.\nSuccessful exploitation necessitates a social engineering component, where an attacker must entice a user to install or interact with a crafted Chrome extension.\nBy leveraging this memory safety issue, an attacker can manipulate the state of the network object life cycle to facilitate memory corruption, potentially leading to unauthorized execution of malicious payloads on the host system.",
"technicalDetails": "The vulnerability resides in the Network stack of the Chromium engine, specifically involving the mismanagement of object memory life cycles. A Use-After-Free (UAF) occurs when a program continues to use a pointer after the memory area it references has been freed or deallocated.\nIn the context of the Chrome Network component, the flaw is triggered when a crafted Chrome extension performs specific operations that lead to the premature destruction of a network-related object. If the internal state tracking mechanism fails to update existing references to this object, the program may subsequently attempt to access or invoke methods on this dangling pointer.\nThe exploitation flow begins with the delivery of a malicious Chrome extension via social engineering. Once installed, the extension interacts with the browser's network APIs in a manner designed to create a race condition or a specific sequence of asynchronous events. This sequence forces the browser to free an object while a secondary component still holds a valid reference to the memory location.\nBy carefully controlling the heap layout through heap spraying or groom techniques, an attacker can replace the freed object with arbitrary data. When the network component subsequently triggers a read or execution operation on the dangling pointer, it inadvertently consumes attacker-controlled data. This primitive can be leveraged to redirect the control flow of the browser process, facilitating execution of arbitrary code.\nCrucially, the exploitation of this UAF enables the attacker to bypass standard browser sandbox protections. While the initial interaction occurs through the extension, the resulting memory corruption allows for execution outside the intended security boundaries of the browser process, granting the attacker a higher degree of control over the host system. The vulnerability affects all Google Chrome versions prior to 155.0.8059.39. There are no authentication requirements for the initial trigger, as the exploit relies on the execution of the crafted extension within the user's browser context."
}