External risk intelligence

Google Chrome Use After Free Allows Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-106358

This vulnerability is located within the Google Chrome browser and requires a user to interact with a crafted HTML page. As a client-side application, it is not a server, edge service, or infrastructure component that is public-facing by design in common deployments.

Use After Free

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Google Chrome, a widely used web browser. This issue, described as a "use after free" flaw in the browser's navigation component, could allow an attacker to execute malicious code outside the browser's security boundaries if a user visits a specially crafted webpage. The potential for attackers to gain unauthorized code execution is a significant concern for any organization relying on web browsing.

  • Browser flaw lets attackers run unwanted code.
  • Requires user interaction with malicious websites.
  • Confirm relevance and exposure to users.

Attack Path

How an attacker could exploit the issue

An attacker could target users by tricking them into visiting a malicious website. This website would contain specially crafted code designed to exploit a flaw in how the Chrome browser handles navigation. If successful, this could allow the attacker to execute their own code on the user's computer, potentially leading to broader system compromise.

  • Requires visiting a malicious page.
  • Exploits a use-after-free flaw.
  • Can lead to arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A use-after-free vulnerability in Chrome's navigation component could allow a remote attacker to execute code outside the browser's sandbox. This may occur when a user visits a specially crafted HTML page.

  • Arbitrary code execution outside the sandbox.
  • Visiting a malicious HTML page.
  • Compromise of user's device.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Chrome's rendering engine requires a user to visit a malicious webpage to trigger code execution outside the sandbox. Identifying affected endpoints, confirming business criticality, and locating the accountable owner are the initial steps. Remediation planning should then be prioritized based on risk and exposure.

  • Identify browser owners and asset inventory.
  • Verify user exposure and impact.
  • Plan coordinated, risk-based updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Chrome and its navigation component?

Google Chrome is a widely used web browser built on the Chromium engine. The navigation component is a core part of the software responsible for processing how users move between websites, handling data requests, and rendering the pages you see. It serves as a vital bridge between the web and your local device.

What does use-after-free mean in CVE-2026-106358?

This is a memory corruption weakness categorized as CWE-416. It occurs when a program continues to use a pointer to a piece of computer memory after that memory has been freed or deleted. In this CVE, an attacker can manipulate this flaw to cause the browser to perform unexpected actions or execute unauthorized code.

How is this navigation flaw triggered?

The flaw is triggered when a user visits a specially crafted HTML page designed to exploit the memory error. It does not trigger through normal web browsing, background network activity, or simply having the browser open. The malicious code must be present on the specific webpage the user navigates to for the bug to execute.

Why should I care if my systems use Chrome?

While Chrome is a client-side application, Halo Surface Signal notes that this vulnerability is unlikely to affect server-side infrastructure directly. However, because it allows code execution outside the browser's sandbox, it poses a high risk to individual endpoints and user devices that interact with untrusted internet content, potentially leading to a total system compromise.

What steps should I take to respond to this issue?

Begin by identifying which systems in your environment have older versions of Chrome installed. Prioritize updating these endpoints to the corrected version to eliminate the vulnerability. Communicate the need for the update to your users or device administrators, ensuring that machines are patched to a version beyond 155.0.8059.39.

References