CVE Record
[ CRITICAL ]CVE-2026-106197
Use-after-free in Chrome Browser component enables sandbox RCE
Use-after-free in Google Chrome's Browser component allows remote code execution inside the sandbox via a crafted HTML page. CVSS 9.6. Patched in Chrome 155.
- Vendor
- Product
- Chrome (Browser component, prior to 155.0.8059.39)
- CVSS
- 9.6
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
CVE-2026-106197 is a use-after-free vulnerability in the Browser component of Google Chrome. A remote attacker can exploit it to execute code inside the renderer sandbox by serving a crafted page.
Reported by researcher Xinyang Ge using AI-assisted vulnerability research techniques. Patched in Chrome 155.0.8059.39 (all platforms), released October 7, 2026. Google reports no active exploitation.
