← Back to search

CVE-2026-102316

9.6 CRITICAL

Published 2026-09-29 · Updated 2026-09-30

AI risk analysis

Summary
This flaw involves a use-after-free vulnerability in Google Chrome's Views component, allowing attackers to execute arbitrary code outside the sandbox via a crafted HTML page, posing a critical risk.
Exploitability
Exploitation is considered high risk and requires social engineering to trick users into visiting a crafted HTML page.
Blast radius
If exploited, the flaw could result in full system compromise, enabling attackers to execute arbitrary code with the highest privileges.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Google Chrome version 154.0.8037.92 or later.
rcewebcriticalbrowsercode-execution

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Use after free in Views in Google Chrome prior to 154.0.8037.92 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Weaknesses

CWE-416

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.