Skip to content
feed: live
0dayNews
CVE Record
[ CRITICAL ]CVE-2026-106358

Use-after-free in Chrome Navigation allows sandbox code execution

Use-after-free in Google Chrome's Navigation component allows remote code execution inside the sandbox via a crafted HTML page. CVSS 9.6. Patched in Chrome 155.

Vendor
Google
Product
Chrome (Navigation component, prior to 155.0.8059.39)
CVSS
9.6
EPSS (exploit probability)
N/A
Status
patched
Published

CVE-2026-106358 is a use-after-free in Google Chrome’s Navigation component. An attacker can trigger it via a crafted HTML page to achieve code execution inside the renderer sandbox.

Reported by Xinyang Ge. Patched in Chrome 155.0.8059.39 (all platforms), released October 7, 2026. No exploitation in the wild reported.