External risk intelligence

Google Chrome Use-After-Free in WindowDialog Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-95356

The vulnerability exists in a web browser, which is inherently designed to navigate and render content from the public internet. While it requires user interaction, the product role as a primary internet-facing application makes it highly probable that the vulnerable component is exposed to untrusted web content in standard deployments.

Use After Free

Google Chrome

before 154.0.8037.57

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in the WindowDialog component of Google Chrome allows a remote attacker, through social engineering, to potentially execute arbitrary code outside the browser's sandbox by directing a user to a malicious webpage.

  • Code execution risk in web browsing.
  • Critical flaw impacts widespread, internet-facing software.
  • Confirm if Chrome is used and versions are vulnerable.

Attack Path

How an attacker could exploit the issue

An attacker could trick a user into visiting a malicious website, which then triggers a flaw in Chrome's WindowDialog component. This flaw could allow the attacker to execute code on the user's computer, escaping the browser's security.

  • No authentication or privileges required.
  • Triggered by visiting a malicious webpage.
  • Risk of arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A use-after-free vulnerability in Chrome's WindowDialog component could allow a remote attacker to execute arbitrary code outside the browser's sandbox. This could occur when a user visits a specially crafted HTML page, which might be delivered through social engineering tactics.

  • Arbitrary code execution in user's browser.
  • User visits malicious HTML page.
  • System compromise, data theft, or further attacks.

Operational Fix

Recommended remediation, mitigation, and detection steps

Technical leaders and security teams should coordinate to manage this critical vulnerability. The first step is to confirm where the affected browser exists, assess its business criticality and reachability, identify the accountable owner, and then prioritize remediation.

  • Own: Application or Infrastructure teams.
  • Verify: Browser exposure and criticality.
  • Action: Plan and execute updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Chrome?

Google Chrome is a widely used web browser built on the Chromium engine. It manages how your computer renders and interacts with web content, including complex interface elements like dialog boxes. Because it acts as the primary gateway between your local system and the internet, it must safely process diverse data from unknown sources to prevent malicious content from accessing your computer's underlying files or processes.

What does a use-after-free vulnerability mean in CVE-2026-95356?

This vulnerability is classified as CWE-416, or use-after-free. It occurs when the browser's WindowDialog component continues to reference a memory location after that memory has already been cleared or released. If an attacker can manipulate this state, they may be able to force the browser to execute unauthorized instructions in that freed memory space, potentially bypassing the security sandbox.

How is this vulnerability triggered?

The trigger requires a user to visit a specially crafted, malicious HTML page, often delivered through social engineering. Simply having the browser installed is not enough; the flaw is only activated when the software processes the specific, malformed content designed to exploit the WindowDialog memory error. Normal, benign web browsing does not trigger this condition.

Is my organization at risk from CVE-2026-95356?

Halo Surface Signal notes that because Google Chrome is inherently designed to navigate the public internet, it is effectively an internet-facing application. Any device running a vulnerable version is exposed to untrusted web content. While the attack requires user interaction to visit a malicious site, the risk is elevated because the browser is constantly interacting with external, potentially compromised, or deceptive sources.

What should I do if I am running an affected version of Chrome?

Your first step is to identify all systems within your environment where Chrome is installed and confirm if they are running a version earlier than 154.0.8037.57. Once identified, prioritize these systems for an update to the latest patched version. Coordinate with your application or infrastructure teams to ensure the update is deployed, as patching the browser is the only way to resolve this specific memory management flaw.

References