Sceawere

Vulnerability Detail

CVE-2026-76040UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Google Chrome Use-After-Free Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
17h ago
Vendor
Google
Product
Chrome
Attack Type
Use after free
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Use after free in Browser in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-18T21:18:28.060Z",
  "pubdate": "2026-08-18T21:18:28.060Z",
  "executiveSummary": "A use-after-free vulnerability exists within the Browser component of Google Chrome on Mac prior to version 151.0.7922.169.\nThe vulnerability allows a remote attacker to achieve arbitrary code execution outside of the security sandbox.\nExploitation requires social engineering to successfully entice a victim into visiting a maliciously crafted HTML page.\nThe severity of this security flaw is classified as High by Chromium security standards.\nSuccessful exploitation poses severe risk implications, potentially leading to full system compromise or unauthorized access to the underlying operating system beyond the confines of the browser isolation boundaries.",
  "technicalDetails": "The vulnerability is rooted in a use-after-free memory corruption flaw located within the Browser component of Google Chrome.\nA use-after-free condition occurs when a program continues to use a pointer after the memory region it references has been deallocated or freed, typically resulting from improper memory management or lifetime handling of dynamic objects.\nThe affected software versions include Google Chrome on Mac prior to 151.0.7922.169.\nThe attack vector involves network exposure where a remote attacker delivers a crafted HTML page to the target user.\nAuthentication and local privilege requirements are minimal for the initial delivery phase, as the attack relies on external web navigation.\nThe step-by-step attack flow begins when the remote attacker leverages social engineering techniques to direct a target user to the malicious HTML page.\nUpon rendering the crafted HTML page, the vulnerable Browser component processes malicious sequences that trigger the use-after-free condition in memory.\nBy manipulating the freed heap memory allocations, the attacker can achieve deterministic control over the dangling pointer.\nThis control facilitates arbitrary code execution capabilities.\nCrucially, the payload behavior enables the execution of malicious code outside of the browser sandbox, breaking containment barriers and interacting directly with the underlying host operating system with the privileges of the user running the browser process."
}
CVE-2026-76040: Google Chrome Use-After-Free Vulnerability (HIGH Severity, CVSS: 8.8) - Sceawere