Sceawere

Vulnerability Detail

CVE-2026-106234UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Use-After-Free in Chrome Network

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.6
Creation Date
6h ago
Vendor
Google
Product
Chrome
Attack Type
Use after free
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.6",
  "pubDate": "2026-10-06T19:17:50.250Z",
  "pubdate": "2026-10-06T19:17:50.250Z",
  "executiveSummary": "A Use-After-Free (UAF) vulnerability exists within the Network component of Google Chrome prior to version 155.0.8059.39.\nThis memory corruption flaw allows a remote attacker to achieve arbitrary code execution beyond the confines of the browser sandbox.\nThe vulnerability is classified as Low severity by Chromium, primarily due to the specific exploitation requirements.\nSuccessful exploitation necessitates a social engineering component, where an attacker must entice a user to install or interact with a crafted Chrome extension.\nBy leveraging this memory safety issue, an attacker can manipulate the state of the network object life cycle to facilitate memory corruption, potentially leading to unauthorized execution of malicious payloads on the host system.",
  "technicalDetails": "The vulnerability resides in the Network stack of the Chromium engine, specifically involving the mismanagement of object memory life cycles. A Use-After-Free (UAF) occurs when a program continues to use a pointer after the memory area it references has been freed or deallocated.\nIn the context of the Chrome Network component, the flaw is triggered when a crafted Chrome extension performs specific operations that lead to the premature destruction of a network-related object. If the internal state tracking mechanism fails to update existing references to this object, the program may subsequently attempt to access or invoke methods on this dangling pointer.\nThe exploitation flow begins with the delivery of a malicious Chrome extension via social engineering. Once installed, the extension interacts with the browser's network APIs in a manner designed to create a race condition or a specific sequence of asynchronous events. This sequence forces the browser to free an object while a secondary component still holds a valid reference to the memory location.\nBy carefully controlling the heap layout through heap spraying or groom techniques, an attacker can replace the freed object with arbitrary data. When the network component subsequently triggers a read or execution operation on the dangling pointer, it inadvertently consumes attacker-controlled data. This primitive can be leveraged to redirect the control flow of the browser process, facilitating execution of arbitrary code.\nCrucially, the exploitation of this UAF enables the attacker to bypass standard browser sandbox protections. While the initial interaction occurs through the extension, the resulting memory corruption allows for execution outside the intended security boundaries of the browser process, granting the attacker a higher degree of control over the host system. The vulnerability affects all Google Chrome versions prior to 155.0.8059.39. There are no authentication requirements for the initial trigger, as the exploit relies on the execution of the crafted extension within the user's browser context."
}
CVE-2026-106234: Use-After-Free in Chrome Network (CRITICAL Severity, CVSS: 9.6) | Sceawere