External risk intelligence

Google Chrome Font Memory Corruption Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-95311

This vulnerability affects a client-side web browser. Exploitation requires user interaction to navigate to a crafted web page, meaning the product is not an internet-facing service or infrastructure component that is public-facing by design.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A free of non-heap memory vulnerability in Google Chrome could allow a remote attacker, through a crafted webpage and social engineering, to execute arbitrary code outside the browser's sandbox. The severity is rated as Critical, indicating a significant potential risk.

  • Vulnerability allows code execution outside browser sandbox.
  • Critical severity means potential for widespread impact.
  • Confirm relevance and exposure to Chrome users.

Attack Path

How an attacker could exploit the issue

Attackers can exploit this vulnerability by tricking users into visiting a malicious webpage, which then triggers a flaw in how Chrome handles fonts. This could allow them to execute code on the user's device, potentially leading to broader system compromise.

  • Requires a crafted HTML page.
  • Vulnerable font handling in Chrome.
  • Potential for arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow a remote attacker to execute arbitrary code outside the sandbox by tricking a user into visiting a malicious HTML page. This could affect the integrity and confidentiality of the user's system when supported by the advisory.

  • User system integrity and confidentiality.
  • Via a crafted HTML page.
  • Arbitrary code execution outside sandbox.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects Google Chrome, which is client-side software. Ownership likely resides with end-user device administrators or potentially the application owners responsible for desktop software deployment and management. The initial practical move is to identify all Chrome installations, assess their reachability and criticality, and then coordinate a plan for updating the browser, considering user impact and maintenance windows.

  • Identify and enumerate Chrome installations.
  • Verify user interaction and network exposure.
  • Plan and execute browser updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Chrome?

Google Chrome is a widely used web browser built on the open-source Chromium engine. It functions as a client-side application that renders HTML, CSS, and JavaScript to display websites. In this context, the browser includes integrated components for managing system resources and font rendering, which are the specific areas affected by this vulnerability.

What does CVE-2026-95311 mean?

This CVE identifies a 'free of non-heap memory' vulnerability, categorized as CWE-590. This means the browser incorrectly manages memory associated with font processing. When this happens, an attacker might be able to manipulate how the browser handles data, potentially causing it to execute unauthorized code outside of the browser's protective sandbox.

How is this vulnerability triggered?

An attacker triggers this by enticing a user to visit a specially crafted HTML page designed to exploit the flawed font-handling process. Importantly, the vulnerability is not triggered by simply having the browser installed or running in the background. It specifically requires the user to actively navigate to a malicious web page.

Do I need to worry about internet-facing exposure?

Halo Surface Signal notes that this vulnerability is 'very unlikely' to be exploited via traditional internet-facing infrastructure because it is a client-side browser issue. Since it relies on user interaction—tricking someone into visiting a page—the primary risk lies with individual users on their devices rather than public-facing servers.

What steps should I take to respond?

Your first step is to identify all systems in your environment running versions of Chrome older than 154.0.8037.57. Once identified, prioritize updating these browsers to the latest patched version. Because this requires user interaction, focus your communication on educating users to avoid suspicious links while coordinating the rollout of the browser update.

References