Threat Advisory

Chrome Flaw Lets Attackers Corrupt Memory with Use-After-Free Bug

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Chrome 155 addresses 247 security flaws, including four Critical and two High-severity vulnerabilities highlighted in the advisory. The Critical vulnerabilities are use-after-free issues that affect Chrome components such as Chromecast, Browser, Navigation, and Track, while the High-severity issues include an authorization flaw in Site Isolation and a type confusion vulnerability in V8.
- CVE-2026-106382 (CVSS 9.6 – Critical): A use-after-free vulnerability in the Chromecast component can cause memory corruption when processing attacker-controlled content, potentially allowing arbitrary code execution.
- CVE-2026-106197 (CVSS 9.6 – Critical): A use-after-free vulnerability in the Browser component can allow specially crafted web content to trigger memory corruption and potentially execute arbitrary code.
- CVE-2026-106358 (CVSS 9.6 – Critical): A use-after-free vulnerability in the Navigation component can be triggered through malicious web content, potentially resulting in memory corruption and arbitrary code execution.
- CVE-2026-102322 (CVSS 9.6 – Critical): An incorrect authorization vulnerability in Chrome's Site Isolation component can weaken a core browser sandbox security boundary and potentially allow unauthorized access to protected resources.
- CVE-2026-106347 (CVSS 8.8 – High): A use-after-free vulnerability in the Track component can result in memory corruption when processing crafted content, potentially enabling code execution.
- CVE-2026-106240 (CVSS 8.8 – High): A type confusion vulnerability in the V8 JavaScript engine can cause memory corruption when processing specially crafted JavaScript, potentially allowing arbitrary code execution.

RECOMMENDATION:

We recommend you to Install the Chrome 155 security update.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Chrome 155 addresses 247 security flaws, including four Critical and two High-severity vulnerabilities highlighted in the advisory. The Critical vulnerabilities are use-after-free issues that affect Chrome components such as Chromecast, Browser, Navigation, and Track, while the High-severity issues include an authorization flaw in Site Isolation and a type confusion vulnerability in V8.
- CVE-2026-106382 (CVSS 9.6 – Critical): A use-after-free vulnerability in the Chromecast component can cause memory corruption when processing attacker-controlled content, potentially allowing arbitrary code execution.
- CVE-2026-106197 (CVSS 9.6 – Critical): A use-after-free vulnerability in the Browser component can allow specially crafted web content to trigger memory corruption and potentially execute arbitrary code.
- CVE-2026-106358 (CVSS 9.6 – Critical): A use-after-free vulnerability in the Navigation component can be triggered through malicious web content, potentially resulting in memory corruption and arbitrary code execution.
- CVE-2026-102322 (CVSS 9.6 – Critical): An incorrect authorization vulnerability in Chrome's Site Isolation component can weaken a core browser sandbox security boundary and potentially allow unauthorized access to protected resources.
- CVE-2026-106347 (CVSS 8.8 – High): A use-after-free vulnerability in the Track component can result in memory corruption when processing crafted content, potentially enabling code execution.
- CVE-2026-106240 (CVSS 8.8 – High): A type confusion vulnerability in the V8 JavaScript engine can cause memory corruption when processing specially crafted JavaScript, potentially allowing arbitrary code execution.

RECOMMENDATION:

We recommend you to Install the Chrome 155 security update.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu