Sceawere

Vulnerability Detail

CVE-2026-95299UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Chrome GPU Use-After-Free Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.6
Creation Date
7h ago
Vendor
Google
Product
Chrome
Attack Type
Use after free
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Use after free in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.6",
  "pubDate": "2026-09-29T18:17:21.837Z",
  "pubdate": "2026-09-29T18:17:21.837Z",
  "executiveSummary": "A critical Use-After-Free (UAF) vulnerability has been identified within the GPU process of Google Chrome, affecting versions prior to 154.0.8037.57. This memory corruption flaw allows a remote attacker to execute arbitrary code outside the established security sandbox environment.\nThe vulnerability originates from improper memory management within the GPU-related components of the browser. By leveraging a specially crafted HTML page, an attacker can manipulate memory states to trigger a UAF condition when the browser attempts to access an object that has already been deallocated.\nSuccessful exploitation grants an attacker the ability to bypass sandbox protections, potentially leading to full system compromise or unauthorized execution of code with the privileges of the rendering process. The impact is categorized as High, necessitating immediate attention due to the potential for remote code execution (RCE) without requiring specific user authentication beyond visiting a malicious web page.",
  "technicalDetails": "The vulnerability is a classic Use-After-Free condition residing within the GPU stack of the Chromium engine. A UAF vulnerability occurs when an application continues to utilize a pointer to a memory location after that memory has been freed or reallocated. In the context of the Chrome GPU process, the flaw typically arises when the browser fails to correctly manage the lifecycle of objects related to hardware acceleration, such as command buffers, textures, or synchronization primitives.\nThe attack flow begins when a user navigates to a maliciously crafted HTML page designed to interact with the GPU through WebGL, WebGPU, or CSS-related hardware acceleration APIs. The attacker provides a sequence of instructions that triggers the premature deallocation of an object, while maintaining an active reference to that object in the GPU process memory space. Once the memory is freed, the attacker may perform heap spraying or memory grooming to occupy the freed memory block with controlled data.\nSubsequent browser operations attempt to access the stale pointer, which now points to attacker-controlled data instead of the original legitimate object. Because the GPU process often operates with distinct privileges and manages complex asynchronous state machines, this violation of memory safety can be leveraged to corrupt function pointers or vtables within the GPU process memory.\nBy redirecting execution flow, the attacker can achieve arbitrary code execution. Crucially, the vulnerability facilitates a sandbox escape; by compromising the GPU process, the attacker can leverage the increased privilege level of the GPU process to move laterally toward the underlying host operating system, effectively bypassing the browser's main security boundary (the sandbox). The exploit does not require the user to perform complex actions other than navigating to the page, making it a highly effective vector for drive-by download attacks. The vulnerability affects all Chromium-based implementations relying on the affected GPU architecture and codebase versions prior to 154.0.8037.57."
}
CVE-2026-95299: Chrome GPU Use-After-Free Vulnerability (CRITICAL Severity, CVSS: 9.6) | Sceawere