External risk intelligence

Google Chrome FullScreen Use After Free Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-102309

The vulnerability exists within a web browser application (Google Chrome). While browsers process external web content, they are client-side software rather than network-facing infrastructure, services, or servers. The exploit requires a user to navigate to a crafted HTML page, placing it in the client-side/user-interaction category rather than public-facing network services.

Use After Free

Google Chrome

before 154.0.8037.92

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security flaw in Google Chrome's FullScreen feature could allow attackers to execute malicious code outside the browser's protected environment. This is accessed through a specially crafted webpage, and while the security severity is rated High, its exploitability is considered very unlikely as it requires user interaction to visit a malicious site.

  • Flaw lets code escape browser sandbox.
  • Requires user to visit a malicious page.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can lure a user into visiting a malicious webpage. When the user's browser loads this page, the vulnerability in the FullScreen feature can be triggered, potentially allowing the attacker to execute arbitrary code on the user's system.

  • Requires user interaction with a malicious page.
  • Triggered by the FullScreen feature.
  • Allows arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A use-after-free vulnerability in Google Chrome's FullScreen feature could allow a remote attacker to execute arbitrary code outside the sandbox when a user visits a specially crafted HTML page. This could affect the integrity and confidentiality of the user's system.

  • Arbitrary code execution outside sandbox.
  • User visits crafted HTML page.
  • Compromise of system integrity and data.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Google Chrome's FullScreen component requires a user to interact with a malicious HTML page to be exploited. The primary responsibility for remediation typically lies with the application owners or platform teams who manage browser deployments, in coordination with security teams to assess exposure. The first practical step is to identify all systems running the affected Chrome version, determine their business criticality and exposure to external websites, and then plan for updates during scheduled maintenance.

  • Application or Platform owners should prioritize this.
  • Verify all Chrome instances are inventoried.
  • Plan and execute updates promptly.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Chrome?

Google Chrome is a widely used web browser that renders HTML, CSS, and JavaScript to display websites. It includes a security sandbox designed to isolate web content from your underlying operating system, preventing malicious websites from accessing your files or system resources even if the browser itself is compromised.

What does CWE-416 mean for CVE-2026-102309?

CWE-416 refers to a 'Use After Free' weakness. In this CVE, it means the browser's FullScreen component tries to access or use memory that it previously cleared or released. This memory management error creates a stability gap that an attacker can manipulate to bypass the browser's sandbox protections and execute unauthorized code on your computer.

How is this vulnerability triggered?

This bug is triggered when a user visits a specifically crafted HTML page designed to exploit the FullScreen feature. It does not trigger simply by having the browser installed or running in the background. The exploit path requires the active participation of the user navigating to a malicious web page.

Is my system at risk if Chrome is not internet-facing?

Halo Surface Signal notes that because this is client-side software, it is not a traditional network-facing service. However, because browsers are designed to process external content from the internet, any device used to browse the web remains a potential point of entry if a user visits a compromised or malicious site.

What should I do to address CVE-2026-102309?

Your first step is to inventory all systems running versions of Google Chrome older than 154.0.8037.92. Once you have identified these instances, prioritize updating the browser to the latest version to patch the FullScreen component. Coordinate with your team to schedule these updates as part of your standard maintenance cycle.

References