External risk intelligence

Chrome AdFilter Use After Free Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-95310

The vulnerability exists within the Google Chrome browser and requires a user to navigate to a crafted HTML page. As a client-side application, it is not a server-side service or internet-facing infrastructure component, making public network exposure of the application surface itself unlikely in the context of this metric.

Use After Free

Google Chrome

before 154.0.8037.57

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in Google Chrome's AdFilter component could allow attackers to execute arbitrary code outside the browser's security sandbox if a user visits a specially crafted webpage. This type of flaw represents a significant risk, as it enables attackers to potentially compromise user systems remotely through web browsing activity.

  • A flaw lets attackers run code through web browsing.
  • Critical risk if malicious sites are visited.
  • Confirm exposure and evaluate browser security.

Attack Path

How an attacker could exploit the issue

A remote attacker can trick a user into visiting a malicious webpage, which then exploits a use-after-free vulnerability in Chrome's AdFilter. This can allow the attacker to execute code on the user's system, potentially breaking out of the browser's security sandbox.

  • Requires visiting a crafted HTML page.
  • Triggered by the AdFilter component.
  • Risk of arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A use-after-free vulnerability in Chrome's AdFilter component could allow a remote attacker to execute arbitrary code outside the browser's sandbox when a user visits a specially crafted HTML page. This could lead to the compromise of the user's browsing session and potentially impact other sandboxed processes.

  • Arbitrary code execution in user's browser.
  • Malicious HTML page and user interaction.
  • Sandbox escape and system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

For this critical vulnerability in Google Chrome, the platform or infrastructure team responsible for managing browser deployments across the organization should take the lead. The initial, practical step is to determine the scope of affected Chrome instances, prioritize those that are internet-facing or handle sensitive data, and identify the specific owner of those endpoints to coordinate remediation.

  • Platform teams own the issue.
  • Verify user exposure and criticality.
  • Plan controlled browser updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Google Chrome AdFilter component?

AdFilter is a specific sub-component within the Google Chrome browser architecture designed to manage, block, or handle advertising content. Users do not interact with it directly; it operates in the background to filter web page elements as the browser processes site code.

What does CWE-416 mean for CVE-2026-95310?

CWE-416 is a Use After Free vulnerability. It occurs when a program continues to use a memory address after that memory has been cleared or released. In this CVE, an attacker manipulates the AdFilter component to reuse this freed memory, potentially allowing them to bypass browser protections and execute malicious code.

How is this Chrome vulnerability triggered?

A remote attacker triggers the flaw by hosting a specially crafted HTML page. The vulnerability requires the user to actively navigate to this malicious site using an affected version of Chrome. Simply having the browser installed or running in the background does not trigger the bug without visiting the harmful page.

Is my machine at risk if it isn't internet-facing?

According to Halo Surface Signal, this vulnerability is client-side, meaning it exists within the browser software itself rather than in server-side infrastructure. While the browser needs to fetch the malicious page from the internet, the threat is driven by user activity—visiting a page—rather than the machine having open network ports or hosting services.

What are the first steps to address this Chrome flaw?

The primary response is to update Google Chrome to version 154.0.8037.57 or later. Organizations should identify which systems are running older, vulnerable versions and coordinate a standard browser update deployment. Prioritize machines that are frequently used for web research or that access sensitive internal resources.

References