Sceawere
Vulnerability Detail
CVE-2026-95277UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Use-After-Free Vulnerability in Views
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.6
- Creation Date
- 7h ago
- Vendor
- Product
- Chrome
- Attack Type
- Use after free
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.6",
"pubDate": "2026-09-29T18:17:19.037Z",
"pubdate": "2026-09-29T18:17:19.037Z",
"executiveSummary": "A critical Use-After-Free (UAF) vulnerability exists within the Views component of Google Chrome, identified in versions prior to 154.0.8037.57. This memory corruption flaw allows a remote, unauthenticated attacker to execute arbitrary code outside the browser's security sandbox.\nThe vulnerability originates from improper management of object lifecycles within the UI framework. By leveraging a specially crafted HTML page, an attacker can trigger a race condition or state manipulation that leads to the reuse of memory previously allocated to a Views object after it has been freed.\nThe impact of successful exploitation is significant, potentially granting an attacker full execution capabilities on the host system. This vulnerability carries a High severity rating, as it bypasses standard sandboxing protections. Exploitation requires user interaction, typically involving the victim visiting a malicious website. Organizations are advised to prioritize updating affected instances of Google Chrome to the patched version or later to mitigate the risk of remote code execution.",
"technicalDetails": "The vulnerability resides in the Views UI toolkit integrated into Chromium. A Use-After-Free (UAF) condition occurs when the application continues to reference a pointer to a memory location after the corresponding object has been deallocated. In the context of the Views framework, this typically involves a failure in the object's reference counting mechanism or an incorrect lifecycle management during complex UI rendering or event handling sequences.\nThe attack flow begins when a remote attacker hosts a malicious HTML document designed to manipulate the browser's DOM or internal UI state. When the victim navigates to this crafted page, the attacker triggers an asynchronous event or a specific sequence of UI operations that causes a Views-related object to be freed prematurely while a dangling pointer remains in an active object or event queue. Due to the deterministic nature of memory allocation within the heap, the attacker may employ heap spraying techniques to populate the previously freed memory space with malicious data or a controlled object structure.\nOnce the UAF condition is triggered, the browser attempts to access or invoke a function pointer or virtual method table (vtable) within the corrupted memory object. If the attacker has successfully controlled the contents of this memory, they can hijack the control flow of the browser process. This redirection of execution allows for the execution of arbitrary code, such as ROP (Return-Oriented Programming) chains, to bypass memory protections like DEP (Data Execution Prevention) and ASLR (Address Space Layout Randomization).\nBecause the vulnerability occurs within the browser environment, successful exploitation can lead to a sandbox escape. By gaining code execution, the attacker can leverage further vulnerabilities in the underlying operating system or browser components to transition from the limited-privilege sandboxed environment to the user's host context. The technical severity is elevated by the lack of requirement for prior authentication or elevated privileges. The exploitation is strictly remote, relying on the browser's parsing and rendering engine to process the malformed content. The affected versions include all Chromium-based implementations prior to 154.0.8037.57, specifically impacting components utilizing the Views infrastructure for UI element management."
}