Sceawere

Vulnerability Detail

CVE-2026-95313UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Google Chrome Fullscreen Use-After-Free

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.6
Creation Date
7h ago
Vendor
Google
Product
Chrome
Attack Type
Use after free
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Use after free in Fullscreen in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.6",
  "pubDate": "2026-09-29T18:17:23.463Z",
  "pubdate": "2026-09-29T18:17:23.463Z",
  "executiveSummary": "This vulnerability is a critical use-after-free (UAF) flaw located within the Fullscreen component of Google Chrome. The vulnerability allows a remote, unauthenticated attacker to execute arbitrary code outside the browser sandbox environment.\nA use-after-free condition occurs when an application continues to use a pointer after the memory area it references has been deallocated or freed, leading to memory corruption. By leveraging a specially crafted HTML page, an attacker can manipulate memory states to trigger this flaw.\nThe impact is severe, as successful exploitation facilitates remote code execution (RCE). Because the flaw allows an attacker to break out of the Chromium sandbox, the breach may lead to full system compromise, data theft, or malware deployment on the host device.\nAffected products include versions of Google Chrome prior to 154.0.8037.57. There are no known authentication or elevated privilege requirements for the attacker, who only needs the victim to visit a malicious webpage, making this a high-risk vector for browser-based attacks.",
  "technicalDetails": "The vulnerability resides within the browser's Fullscreen handling logic, which manages the transition and state of elements entering or exiting full-screen mode. The root cause is a use-after-free defect, wherein the internal object representation of the fullscreen element is deallocated while a reference to that object remains active in the rendering pipeline.\nThe attack flow begins when a user navigates to a maliciously crafted HTML document. The attacker utilizes JavaScript to trigger rapid transitions or specific layout manipulations during the fullscreen state change. This process forces the rendering engine to free the memory associated with the fullscreen object while a dangling pointer remains in a reachable memory location or global object.\nExploitation involves heap grooming or heap spraying techniques, where the attacker fills the freed memory space with controlled data. Once the application attempts to access the dangling pointer, it inadvertently interacts with the attacker-controlled memory. By carefully structuring the payload, the attacker can hijack the control flow—for instance, by overwriting a virtual method table (vtable) pointer or a callback function—to redirect execution to a malicious instruction sequence.\nBecause the vulnerability exists in the rendering process, the successful redirection of execution permits the attacker to bypass standard browser security boundaries. The Chromium sandbox is intended to contain such memory corruption issues, but in this specific instance, the flaw is capable of facilitating sandbox escape. This allows the attacker to execute native code at the privilege level of the browser process, or move laterally toward system-level execution depending on the host environment's kernel-level protections.\nThe vulnerability affects Chromium-based architectures in Google Chrome versions earlier than 154.0.8037.57. It requires no specific user interaction beyond the initial navigation to the malicious URL. The payload behavior is stealthy, often designed to execute in the background during the rendering phase, leaving minimal traces for standard web-based security monitors."
}
CVE-2026-95313: Google Chrome Fullscreen Use-After-Free (CRITICAL Severity, CVSS: 9.6) | Sceawere