CVE Record
[ CRITICAL ]CVE-2026-106358
Use-after-free in Chrome Navigation allows sandbox code execution
Use-after-free in Google Chrome's Navigation component allows remote code execution inside the sandbox via a crafted HTML page. CVSS 9.6. Patched in Chrome 155.
- Vendor
- Product
- Chrome (Navigation component, prior to 155.0.8059.39)
- CVSS
- 9.6
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
CVE-2026-106358 is a use-after-free in Google Chrome’s Navigation component. An attacker can trigger it via a crafted HTML page to achieve code execution inside the renderer sandbox.
Reported by Xinyang Ge. Patched in Chrome 155.0.8059.39 (all platforms), released October 7, 2026. No exploitation in the wild reported.
