Sceawere
Vulnerability Detail
CVE-2026-95339UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ServiceWorker Use-After-Free Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.6
- Creation Date
- 7h ago
- Vendor
- Product
- Chrome
- Attack Type
- Use after free
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Use after free in ServiceWorker in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.6",
"pubDate": "2026-09-29T18:17:26.480Z",
"pubdate": "2026-09-29T18:17:26.480Z",
"executiveSummary": "This vulnerability is a critical Use-After-Free (UAF) flaw located within the ServiceWorker implementation of Google Chrome. The vulnerability allows a remote, unauthenticated attacker to achieve arbitrary code execution outside the browser's security sandbox.\nThe flaw stems from improper memory management during the lifecycle of a ServiceWorker, where a pointer to an object remains accessible after the memory has been deallocated. By leveraging a specially crafted HTML page, an attacker can trigger this memory corruption, leading to a state where the browser executes attacker-controlled code.\nGiven the nature of the exploit—remote code execution originating from web content—the risk to end-users is extreme. The vulnerability facilitates full system compromise if the attacker can escape the sandbox environment. Affected versions of Google Chrome include all releases prior to 154.0.8037.57. Successful exploitation does not require the user to perform privileged actions, as navigation to a malicious site is sufficient to trigger the exploitation chain.\nThe criticality of this vulnerability is underscored by its ability to bypass standard sandbox protections, posing a significant threat to user data confidentiality, integrity, and system availability.",
"technicalDetails": "The vulnerability resides within the Chrome ServiceWorker component, specifically related to the management of object lifetimes during asynchronous operations. A Use-After-Free (UAF) condition occurs when the browser engine fails to correctly track the reference count or lifecycle state of a service worker-related object. When the memory for this object is freed, but a dangling pointer remains in a reachable memory structure, the subsequent access to this memory location results in a UAF primitive.\nThe attack flow begins when a remote attacker hosts a crafted HTML page containing malicious JavaScript designed to interact with the ServiceWorker API. The attacker induces a state change or an asynchronous operation that triggers the premature deallocation of the target object while the engine still maintains a reference to it. By precisely manipulating the heap layout—a technique often involving heap spraying or grooming—the attacker ensures that the freed memory is reallocated to hold attacker-controlled data.\nOnce the attacker successfully overwrites the memory slot, they trigger the dangling pointer, causing the browser to execute data previously planted in the heap as if it were a legitimate function pointer or control structure. Because this occurs within the context of the renderer process and involves vulnerabilities that allow for sandbox escape, the payload can achieve arbitrary code execution on the host operating system.\nThis vulnerability is particularly dangerous because the ServiceWorker API operates independently of the main browser thread, allowing for complex asynchronous exploitation scenarios. The exploitation does not require specific user authentication or administrative privileges; the process is fully automated once a victim loads the malicious document. The post-exploitation impact includes the potential for persistent malware installation, data exfiltration, or complete loss of control over the local execution environment, as the sandbox boundary is effectively neutralized by the arbitrary code execution capability."
}