External risk intelligence

Use after free in Google Chrome Views allows code execution

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-95277

This vulnerability exists within the Google Chrome web browser, which is a client-side application. It requires a user to navigate to a crafted HTML page, meaning it is not a public-facing service, gateway, or network infrastructure component that is reachable or listening on the internet by design.

Use After Free

Google Chrome

before 154.0.8037.57

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Google Chrome's Views component could allow attackers to execute code outside the sandbox through a malicious webpage. This is a serious security concern because it affects a widely used application and could potentially lead to unauthorized code execution. The main concern at this time is confirming if our organization is exposed.

  • Flaw in Chrome could let attackers run code.
  • Users could be harmed by visiting bad websites.
  • Confirm relevance and exposure to this threat.

Attack Path

How an attacker could exploit the issue

An attacker can entice a user to visit a malicious website, leading to a use-after-free vulnerability in Chrome's Views component. This could allow the attacker to execute code outside the browser's security sandbox.

  • Requires user to visit a malicious page.
  • Triggered by a crafted HTML page.
  • Potential for arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A use-after-free vulnerability in Chrome's Views component could allow a remote attacker to execute arbitrary code outside the sandbox when a user visits a specially crafted HTML page. This could affect the integrity and confidentiality of the user's system.

  • Arbitrary code execution in the browser.
  • Via a malicious HTML page.
  • Compromised user system integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Google Chrome's Views component requires immediate attention from teams responsible for managing end-user computing environments and browser security. The first practical step is to identify all Chrome instances, confirm their exposure to potentially malicious websites, and assess their business criticality. Subsequently, owners should be identified to coordinate the remediation effort, potentially involving vendor engagement or temporary risk reduction measures if immediate patching is not feasible.

  • Owner: End-user computing or browser security teams.
  • Verify: User exposure to malicious sites.
  • Action: Plan controlled updates or mitigations.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Chrome and the Views component?

Google Chrome is a web browser used for navigating the internet. It uses the Views component as a core part of its interface architecture to manage how visual elements, such as windows and buttons, are drawn and displayed to the user.

What does use-after-free mean in CVE-2026-95277?

This is a memory management error classified as CWE-416. It occurs when a program continues to use a pointer to a memory location after that memory has been freed. In this CVE, an attacker can manipulate this flaw to potentially run unauthorized code on the host system.

How is this Chrome vulnerability triggered?

The flaw is triggered when a user navigates to a specifically crafted HTML page designed to exploit the memory error. It is not triggered by simply having the browser installed or running; it requires the active rendering of malicious web content.

Do I need to worry about this if I use Chrome?

Halo Surface Signal indicates this is a client-side risk. Because it requires a user to visit a malicious site, it is not an internet-facing service or infrastructure component listening for connections. However, any user browsing the web remains a potential target.

When should I update Google Chrome?

You should update to version 154.0.8037.57 or later as soon as possible. Teams managing end-user devices should coordinate these updates to ensure all installations of the browser are patched against the arbitrary code execution risk.

References