OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-95298

HIGH · CVSS 7.8 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in the browser component of Google Chrome prior to version 154.0.8037.57 allows local attackers to execute arbitrary code outside the sandbox through user interface interactions. This high-severity flaw poses significant risks to users, particularly in environments where untrusted content is accessed. Organizations and individuals using affected versions of Chrome should prioritize updating to mitigate potential exploitation.

CVE
CVE-2026-95298
Severity
HIGH
CVSS
7.8
EPSS
0.17%
Chrome

Original NVD Description

Use after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)

Related CVEs

Other vulnerabilities affecting the same vendor(s)