CVE Record
[ HIGH ]CVE-2026-106347
Use-after-free in Chrome Track component allows sandbox code execution
Use-after-free in Google Chrome's Track component allows code execution inside the sandbox via a crafted HTML page. CVSS 8.8 per NVD; Chromium rates it critical internally. Patched in Chrome 155.
- Vendor
- Product
- Chrome (Track component, prior to 155.0.8059.39)
- CVSS
- 8.8
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
CVE-2026-106347 is a use-after-free in Google Chrome’s Track component. A remote attacker can exploit it via a crafted HTML page to run code inside the renderer sandbox.
Reported by Xinyang Ge. NVD rates this CVSS 8.8 (high). Chromium’s internal severity label is “critical.” Patched in Chrome 155.0.8059.39, released October 7, 2026. No exploitation in the wild reported.
