Skip to content
feed: live
0dayNews
CVE Record
[ HIGH ]CVE-2026-106347

Use-after-free in Chrome Track component allows sandbox code execution

Use-after-free in Google Chrome's Track component allows code execution inside the sandbox via a crafted HTML page. CVSS 8.8 per NVD; Chromium rates it critical internally. Patched in Chrome 155.

Vendor
Google
Product
Chrome (Track component, prior to 155.0.8059.39)
CVSS
8.8
EPSS (exploit probability)
N/A
Status
patched
Published

CVE-2026-106347 is a use-after-free in Google Chrome’s Track component. A remote attacker can exploit it via a crafted HTML page to run code inside the renderer sandbox.

Reported by Xinyang Ge. NVD rates this CVSS 8.8 (high). Chromium’s internal severity label is “critical.” Patched in Chrome 155.0.8059.39, released October 7, 2026. No exploitation in the wild reported.