External risk intelligence

Chrome ServiceWorker Use After Free Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-95339

This vulnerability affects a client-side web browser. While it requires the user to load a crafted page, the browser is not a public-facing server, gateway, or network-accessible service that accepts unsolicited inbound connections from the internet.

Use After Free

Google Chrome

before 154.0.8037.57

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in Chrome's ServiceWorker could allow an attacker to execute arbitrary code outside the sandbox by tricking a user into visiting a malicious webpage. This means a user could be prompted to download malware or have their system compromised.

  • Browser flaw lets attackers run code remotely.
  • Affects user browsing, could lead to system compromise.
  • Confirm if Chrome is used and users visit unknown sites.

Attack Path

How an attacker could exploit the issue

A remote attacker could trick a user into visiting a malicious webpage to trigger a use-after-free vulnerability within Chrome's ServiceWorker component. Successful exploitation could allow the attacker to execute arbitrary code, bypassing Chrome's security sandbox.

  • Requires user to visit a malicious page.
  • Triggered by a crafted HTML page.
  • Allows arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A use-after-free vulnerability in Chrome's Service Worker could allow a remote attacker to execute arbitrary code outside the sandbox when a user visits a specially crafted HTML page. This could affect the integrity and availability of the user's system.

  • User's system and data.
  • Visiting a malicious web page.
  • Arbitrary code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Google Chrome's ServiceWorker component requires immediate attention from teams responsible for endpoint security and application owners. The primary first step is to identify all Chrome instances within the environment, determine their exposure, and confirm if they are business-critical, before planning a coordinated remediation.

  • Endpoint security and application owners
  • Verify Chrome installations and exposure
  • Plan and coordinate browser updates

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the ServiceWorker component in Google Chrome?

ServiceWorkers are scripts that run in the background of your browser, separate from a web page. They enable features like offline access, push notifications, and background synchronization by acting as a proxy between the web application, the browser, and the network.

How does a use-after-free vulnerability work in CVE-2026-95339?

This weakness (CWE-416) occurs when a program continues to use a memory address after that memory has been cleared or freed. In this CVE, an attacker can manipulate this state to trick the browser into executing unauthorized commands, effectively bypassing security barriers designed to keep your system safe.

Is this vulnerability triggered automatically by just having the browser open?

No, simply having Chrome open does not trigger this. The attack requires a user to actively navigate to and load a specifically crafted, malicious HTML page. If you do not visit the compromised site, the code responsible for the vulnerability will not execute.

Why should I care about CVE-2026-95339 if Chrome is a client app?

While Halo Surface Signal notes that browsers are not public-facing servers, this flaw is dangerous because it targets the primary tool you use to interact with the internet. If exploited, it can break out of the browser's sandbox, potentially allowing an attacker to compromise your local system and data regardless of your network's perimeter security.

What should I do first to address this Chrome vulnerability?

Your primary step is to ensure all Chrome instances are updated to version 154.0.8037.57 or later. Since this is a client-side update, verify that your deployment management tools have pushed this version to all endpoints. If you cannot update immediately, encourage users to avoid clicking unknown or suspicious links.

References