External risk intelligence

Google Chrome Fullscreen Use After Free Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-95313

The vulnerability exists in a web browser, which is designed to process arbitrary, untrusted content from the public internet as its primary function. While it requires user interaction to visit a crafted page, the application itself is fundamentally an internet-facing tool used to access external resources, making exposure to malicious content highly probable in normal use.

Use After Free

Google Chrome

before 154.0.8037.57

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in Google Chrome's fullscreen functionality could allow attackers to execute code outside the browser's security sandbox using a specially crafted webpage. This could potentially lead to broader system compromise if users are tricked into visiting such pages.

  • A browser flaw allows malicious code execution.
  • It impacts widely used internet-facing software.
  • Confirm relevance and understand potential exposure.

Attack Path

How an attacker could exploit the issue

A remote attacker could trick a user into visiting a malicious website, leading to the execution of arbitrary code outside the browser's sandbox.

  • Entry condition: No privileges needed.
  • Trigger point: Visiting a crafted HTML page.
  • Resulting risk: Code execution outside sandbox.

Live Threat

Current exploitation, exposure, and threat context

A use-after-free vulnerability in Chrome's fullscreen feature could allow a remote attacker to execute arbitrary code outside the sandbox when a user visits a crafted HTML page. This means sensitive system data or user information might be compromised, or the service's behavior could be altered, under conditions supported by the advisory.

  • Arbitrary code execution outside sandbox.
  • Malicious HTML page visited by user.
  • Compromise of system or user data.

Operational Fix

Recommended remediation, mitigation, and detection steps

The "use after free" vulnerability in Google Chrome's Fullscreen feature necessitates action from teams responsible for browser deployments and user security. The initial step involves identifying all instances of the affected Chrome version across the organization, assessing their exposure to the internet or untrusted internal networks, and determining their criticality to business operations. Once identified and prioritized, the appropriate team, likely application or endpoint management, should coordinate with vendor management if a managed service is involved, to plan and execute remediation.

  • Own the issue: Endpoint management or application owners.
  • Verify first: Identify affected Chrome instances.
  • Action: Plan and coordinate updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Chrome and how does it function?

Google Chrome is a widely used web browser built on the Chromium engine. It acts as a gateway for users to access the internet by rendering HTML, CSS, and JavaScript. Its core job is to safely process and display content from various websites while maintaining a security sandbox to isolate browser activities from the underlying operating system.

What does this use-after-free vulnerability mean?

This vulnerability is classified as CWE-416: Use After Free. It occurs when a program continues to use a pointer to memory after that memory has been cleared or released. In CVE-2026-95313, an attacker can manipulate this state within Chrome's fullscreen feature to confuse the browser, potentially allowing them to run unauthorized code outside the security sandbox.

How is this vulnerability triggered by an attacker?

The flaw is triggered when a user visits a specifically crafted malicious website. The vulnerability relies on the browser processing this harmful page; it does not trigger through standard browser use on legitimate sites or by simply having the application installed. Interaction is a required prerequisite for the exploit path to initiate.

Why is this Chrome vulnerability relevant to me?

Halo Surface Signal notes that because Chrome is fundamentally designed to interact with untrusted content from the public internet, the risk of encountering a malicious page is high. If your systems run an affected version, the browser's role as an internet-facing tool makes exposure to this vulnerability a significant concern for your security posture.

What should I do if I am running an affected version?

Your first step is to identify all instances of Chrome within your environment that are running versions prior to 154.0.8037.57. Once you have an inventory of affected systems, coordinate with your endpoint or application management teams to prioritize and apply the necessary updates provided by the vendor to eliminate this flaw.

References