External risk intelligence

Google Chrome Updater Use After Free on Mac

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-95347

The vulnerability affects the Google Chrome browser's updater component on macOS. Browser updaters are client-side processes that typically operate within a local environment rather than acting as internet-facing services, gateways, or public-facing endpoints.

Use After Free

Google Chrome

before 154.0.8037.57

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in the Google Chrome browser's update mechanism on macOS, which could allow a remote attacker to execute arbitrary code. While the technical impact is rated critical, its direct impact on our core business operations is currently assessed as very unlikely due to the nature of the affected component.

  • A flaw exists in Chrome's updater for Mac.
  • It allows attackers code execution outside the sandbox.
  • Confirm relevance and exposure to our environment.

Attack Path

How an attacker could exploit the issue

An attacker could send specially crafted network traffic to a user's Mac running a vulnerable version of Google Chrome. This traffic would target the browser's updater component, which, if mishandled due to a use-after-free flaw, could allow the attacker to execute code beyond the browser's security sandbox.

  • No special access required.
  • Network traffic triggers updater flaw.
  • Arbitrary code execution outside sandbox.

Live Threat

Current exploitation, exposure, and threat context

A remote attacker could execute arbitrary code outside the sandbox by sending crafted network traffic when a user interacts with a vulnerable version of Google Chrome on macOS.

  • Arbitrary code execution.
  • Crafted network traffic.
  • Compromised system.

Operational Fix

Recommended remediation, mitigation, and detection steps

For this vulnerability, the Chrome application owners and the platform or infrastructure teams responsible for managing macOS systems are likely to be involved. The first practical step is to identify all macOS endpoints running the affected Chrome version, confirm their reachability and business criticality, and then assign ownership for remediation planning.

  • App owners and infrastructure teams should own.
  • Verify Chrome version and macOS reachability.
  • Plan remediation based on asset criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Google Chrome Updater for macOS?

It is a background component integrated into the Chrome browser specifically designed to check for, download, and install software updates on Mac systems. It operates independently of the main browser window to ensure users have the latest security patches and features installed.

What does a use-after-free vulnerability mean in CVE-2026-95347?

This weakness, classified as CWE-416, occurs when a program continues to use a memory location after that memory has been cleared or freed. Because the program incorrectly references this invalid memory, an attacker can manipulate the state of the application to execute unauthorized code.

How is CVE-2026-95347 triggered?

An attacker triggers this by sending specially crafted network traffic to the Chrome updater. It is important to note that normal browser activity, such as loading standard websites or interacting with legitimate web services, does not automatically trigger this vulnerability.

Is my Mac at risk from CVE-2026-95347?

Halo Surface Signal indicates this is unlikely for most environments because the updater is a client-side process, not an internet-facing service or public endpoint. You should focus on endpoints where users actively browse the web, as the component is typically local to the machine.

What should I do if I run Google Chrome on macOS?

Your first step is to identify all macOS endpoints in your fleet that are running versions of Chrome older than 154.0.8037.57. Once identified, coordinate with your infrastructure or application teams to update the browser to the latest version to resolve the flaw.

References