CVE & CISA-KEV Catalog
Want to know which of these are on your machines? Scan your endpoints with the free CVE scanner, 200 endpoints free.
| Severity | Description | ||||||
|---|---|---|---|---|---|---|---|
| CVE-2026-69896 | High | 7.0 v3 | 0.3% | - | Fix available | 2026-10-13 | Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally. |
| CVE-2026-95702 | High | 8.5 v4 | - | - | -No fix available yet | 2026-10-09 | Use-after-free vulnerability in VFS in Google gVisor prior to release 20260831.0 on all platforms allows a local attacker with standard container privileges to achieve code execution in the host sentry process by double-freeing the backing MemoryFile from an in-sandbox overlay filesystem. The sentry process remains confined by host-level Linux seccomp and namespace boundaries. |
| CVE-2026-5759 | Critical | 9.8 v3 | 0.6% | - | -No fix available yet | 2026-10-09 | A double free and use-after-free vulnerability in the RdbLoadDeletedNodes function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.1 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service or execute arbitrary code in the redis-server process by supplying a crafted RDB stream whose deleted-nodes buffer length is not a multiple of sizeof(NodeID). The length check relies on ASSERT(), which is compiled out in release builds, so the function continues after freeing the buffer, reading it and freeing it a second time. |
| CVE-2026-14508 | Medium | 6.5 v3 | 0.2% | - | -No fix available yet | 2026-10-08 | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service and obtain sensitive information due to a use-after-free. |
| CVE-2026-107209 | Medium | 5.9 v3 | 0.3% | - | Fix available | 2026-10-07 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, when ImageMagick is built without Cairo support, a crafted RSVG image that reaches a resource limit can cause the RSVG decoder to free image state twice and then use freed memory, crashing the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55. |
| CVE-2026-107167 | Medium | 6.2 v3 | 0.1% | - | -No fix available yet | 2026-10-07 | A flaw was found in m17n-lib. A user providing specially crafted text input can trigger a heap use-after-free condition during input-method state transitions. Under specific conditions, the library frees an internal input context object but subsequently attempts to write to that freed memory. This issue can cause applications relying on the library to crash, leading to a Denial of Service (DoS), or potentially allow arbitrary code execution. |
| CVE-2026-107183 | High | 8.1 v3 | 0.4% | - | -No fix available yet | 2026-10-07 | llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_mapper::map that allows unauthenticated remote attackers to corrupt heap memory via a dangling current_tool pointer. Attackers can submit a chat_parser in a POST /completion request emitting a tool-id after a tool-close tag to crash llama-server and shape a heap write primitive. |
| CVE-2026-69470 | High | 7.0 v3 | 0.3% | - | Fix available | 2026-10-07 | Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally. |
| CVE-2026-57941 | Critical | 9.8 v3 | 0.6% | - | Fix available | 2026-10-07 | Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. |
| CVE-2026-55330 | Critical | 9.8 v3 | 0.3% | - | -No fix available yet | 2026-10-06 | In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. |
| CVE-2026-106423 | High | 8.8 v3 | 0.3% | - | Fix available | 2026-10-06 | Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106421 | High | 8.8 v3 | 0.3% | - | Fix available | 2026-10-06 | Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106419 | Critical | 9.6 v3 | 0.3% | - | Fix available | 2026-10-06 | Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106411 | High | 8.8 v3 | 0.3% | - | Fix available | 2026-10-06 | Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106393 | High | 8.3 v3 | 0.3% | - | Fix available | 2026-10-06 | Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106383 | High | 8.8 v3 | 0.3% | - | Fix available | 2026-10-06 | Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106382 | Critical | 9.6 v3 | 0.4% | - | Fix available | 2026-10-06 | Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) |
| CVE-2026-106373 | High | 8.8 v3 | 0.3% | - | Fix available | 2026-10-06 | Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2026-106358 | Critical | 9.6 v3 | 0.4% | - | -No fix available yet | 2026-10-06 | Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) |
| CVE-2026-106357 | High | 8.8 v3 | 0.5% | - | -No fix available yet | 2026-10-06 | Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106349 | High | 8.8 v3 | 0.3% | - | -No fix available yet | 2026-10-06 | Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106347 | High | 8.8 v3 | 0.3% | - | -No fix available yet | 2026-10-06 | Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Critical) |
| CVE-2026-106335 | High | 8.8 v3 | 0.3% | - | Fix available | 2026-10-06 | Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2026-106318 | High | 8.8 v3 | 0.3% | - | Fix available | 2026-10-06 | Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106315 | High | 8.8 v3 | 0.3% | - | Fix available | 2026-10-06 | Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2026-106298 | Critical | 9.6 v3 | 0.3% | - | Fix available | 2026-10-06 | Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106291 | High | 8.8 v3 | 0.3% | - | Fix available | 2026-10-06 | Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2026-106283 | High | 8.8 v3 | 0.3% | - | Fix available | 2026-10-06 | Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2026-106281 | Critical | 9.6 v3 | 0.3% | - | Fix available | 2026-10-06 | Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106278 | High | 8.8 v3 | 0.3% | - | Fix available | 2026-10-06 | Use after free in Select in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106269 | High | 8.8 v3 | 0.3% | - | Fix available | 2026-10-06 | Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low) |
| CVE-2026-106268 | High | 8.8 v3 | 0.4% | - | Fix available | 2026-10-06 | Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106257 | High | 8.8 v3 | 0.3% | - | Fix available | 2026-10-06 | Use after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106248 | High | 8.8 v3 | 0.3% | - | Fix available | 2026-10-06 | Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106235 | High | 8.8 v3 | 0.4% | - | Fix available | 2026-10-06 | Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106234 | Critical | 9.6 v3 | 0.3% | - | Fix available | 2026-10-06 | Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Low) |
| CVE-2026-106233 | High | 8.3 v3 | 0.4% | - | Fix available | 2026-10-06 | Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106227 | Critical | 9.6 v3 | 0.4% | - | Fix available | 2026-10-06 | Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106211 | Critical | 9.6 v3 | 0.5% | - | Fix available | 2026-10-06 | Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106204 | High | 8.8 v3 | 0.4% | - | Fix available | 2026-10-06 | Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High) |
| CVE-2026-106200 | High | 8.8 v3 | 0.4% | - | Fix available | 2026-10-06 | Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106197 | Critical | 9.6 v3 | 0.5% | - | Fix available | 2026-10-06 | Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) |
| CVE-2026-106193 | High | 8.8 v3 | 0.4% | - | Fix available | 2026-10-06 | Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-106190 | High | 8.8 v3 | 0.4% | - | Fix available | 2026-10-06 | Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2026-57559 | High | 7.8 v3 | 0.1% | - | -No fix available yet | 2026-10-06 | Memory corruption while processing service requests. |
| CVE-2026-57555 | High | 7.8 v3 | 0.1% | - | -No fix available yet | 2026-10-06 | Memory Corruption when executing system service routines due to improper handling of user input buffers. |
| CVE-2026-57554 | High | 7.8 v3 | 0.1% | - | -No fix available yet | 2026-10-06 | Memory Corruption when asynchronous threads access shared performance counter data simultaneously during FastRPC invocations. |
| CVE-2026-57537 | High | 7.8 v3 | 0.1% | - | -No fix available yet | 2026-10-06 | Memory Corruption when accessing and modifying geographic mapping data concurrently without proper synchronization. |
| CVE-2026-25291 | High | 7.8 v3 | 0.1% | - | -No fix available yet | 2026-10-06 | Memory corruption when performing concurrent operations on shared memory page lists due to lack of proper synchronization mechanisms. |
| CVE-2026-25274 | Medium | 6.7 v3 | 0.1% | - | -No fix available yet | 2026-10-06 | Memory Corruption when processing concurrent DMA buffer allocation and deallocation commands without proper synchronization. |
- HighCVSS 7.0 v3·EPSS 0.3%·Fix available
Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
Published 2026-10-13
- HighCVSS 8.5 v4·EPSS -·No fix yet
Use-after-free vulnerability in VFS in Google gVisor prior to release 20260831.0 on all platforms allows a local attacker with standard container privileges to achieve code execution in the host sentry process by double-freeing the backing MemoryFile from an in-sandbox overlay filesystem. The sentry process remains confined by host-level Linux seccomp and namespace boundaries.
Published 2026-10-09
- CriticalCVSS 9.8 v3·EPSS 0.6%·No fix yet
A double free and use-after-free vulnerability in the RdbLoadDeletedNodes function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.1 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service or execute arbitrary code in the redis-server process by supplying a crafted RDB stream whose deleted-nodes buffer length is not a multiple of sizeof(NodeID). The length check relies on ASSERT(), which is compiled out in release builds, so the function continues after freeing the buffer, reading it and freeing it a second time.
Published 2026-10-09
- MediumCVSS 6.5 v3·EPSS 0.2%·No fix yet
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to cause a denial of service and obtain sensitive information due to a use-after-free.
Published 2026-10-08
- MediumCVSS 5.9 v3·EPSS 0.3%·Fix available
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-30 and 6.9.13-55, when ImageMagick is built without Cairo support, a crafted RSVG image that reaches a resource limit can cause the RSVG decoder to free image state twice and then use freed memory, crashing the process. This issue is fixed in versions 7.1.2-30 and 6.9.13-55.
Published 2026-10-07
- MediumCVSS 6.2 v3·EPSS 0.1%·No fix yet
A flaw was found in m17n-lib. A user providing specially crafted text input can trigger a heap use-after-free condition during input-method state transitions. Under specific conditions, the library frees an internal input context object but subsequently attempts to write to that freed memory. This issue can cause applications relying on the library to crash, leading to a Denial of Service (DoS), or potentially allow arbitrary code execution.
Published 2026-10-07
- HighCVSS 8.1 v3·EPSS 0.4%·No fix yet
llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_mapper::map that allows unauthenticated remote attackers to corrupt heap memory via a dangling current_tool pointer. Attackers can submit a chat_parser in a POST /completion request emitting a tool-id after a tool-close tag to crash llama-server and shape a heap write primitive.
Published 2026-10-07
- HighCVSS 7.0 v3·EPSS 0.3%·Fix available
Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
Published 2026-10-07
- CriticalCVSS 9.8 v3·EPSS 0.6%·Fix available
Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Published 2026-10-07
- CriticalCVSS 9.8 v3·EPSS 0.3%·No fix yet
In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.3%·Fix available
Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.3%·Fix available
Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- CriticalCVSS 9.6 v3·EPSS 0.3%·Fix available
Use after free in ANGLE in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.3%·Fix available
Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- HighCVSS 8.3 v3·EPSS 0.3%·Fix available
Use after free in Storage in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.3%·Fix available
Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- CriticalCVSS 9.6 v3·EPSS 0.4%·Fix available
Use after free in Chromecast in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.3%·Fix available
Use after free in Fonts in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-10-06
- CriticalCVSS 9.6 v3·EPSS 0.4%·No fix yet
Use after free in Navigation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.5%·No fix yet
Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.3%·No fix yet
Use after free in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.3%·No fix yet
Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.3%·Fix available
Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.3%·Fix available
Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.3%·Fix available
Use after free in Modularization in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-10-06
- CriticalCVSS 9.6 v3·EPSS 0.3%·Fix available
Use after free in Chrome Tabs in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.3%·Fix available
Use after free in GarbageCollection in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.3%·Fix available
Use after free in Streaming in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-10-06
- CriticalCVSS 9.6 v3·EPSS 0.3%·Fix available
Use after free in Tint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.3%·Fix available
Use after free in Select in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.3%·Fix available
Use after free in CSS in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.4%·Fix available
Use after free in WebRTC in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.3%·Fix available
Use after free in HTML in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.3%·Fix available
Use after free in Bindings in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.4%·Fix available
Use after free in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- CriticalCVSS 9.6 v3·EPSS 0.3%·Fix available
Use after free in Network in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: Low)
Published 2026-10-06
- HighCVSS 8.3 v3·EPSS 0.4%·Fix available
Use after free in Metrics in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- CriticalCVSS 9.6 v3·EPSS 0.4%·Fix available
Use after free in Core in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- CriticalCVSS 9.6 v3·EPSS 0.5%·Fix available
Use after free in TabStrip in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.4%·Fix available
Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.4%·Fix available
Use after free in Track in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- CriticalCVSS 9.6 v3·EPSS 0.5%·Fix available
Use after free in Browser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.4%·Fix available
Use after free in Parser in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- HighCVSS 8.8 v3·EPSS 0.4%·Fix available
Use after free in Media in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-10-06
- HighCVSS 7.8 v3·EPSS 0.1%·No fix yet
Memory corruption while processing service requests.
Published 2026-10-06
- HighCVSS 7.8 v3·EPSS 0.1%·No fix yet
Memory Corruption when executing system service routines due to improper handling of user input buffers.
Published 2026-10-06
- HighCVSS 7.8 v3·EPSS 0.1%·No fix yet
Memory Corruption when asynchronous threads access shared performance counter data simultaneously during FastRPC invocations.
Published 2026-10-06
- HighCVSS 7.8 v3·EPSS 0.1%·No fix yet
Memory Corruption when accessing and modifying geographic mapping data concurrently without proper synchronization.
Published 2026-10-06
- HighCVSS 7.8 v3·EPSS 0.1%·No fix yet
Memory corruption when performing concurrent operations on shared memory page lists due to lack of proper synchronization mechanisms.
Published 2026-10-06
- MediumCVSS 6.7 v3·EPSS 0.1%·No fix yet
Memory Corruption when processing concurrent DMA buffer allocation and deallocation commands without proper synchronization.
Published 2026-10-06
Free CVE lookup by TridentStack Control, automated patching for Windows, macOS, and Linux fleets. Learn more·Uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog.