CVE-2026-106421 — Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …
Description
Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
Required
User Interaction
S
Unchanged
Scope
C
High
Confidentiality
I
High
Integrity
A
High
Availability
Affected
- Vendor
- Product
- chrome
Versions
- < 155.0.8059.39
Stated as the source expressed them.
References
Related threats
same CWE or vendorCVE-2026-14508 — IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a re…
CVE-2026-14508 · 9h ago
CVE-2026-105824 — ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a use-after-free vulnerability in the RSVG decoder when built without cairo support, …
CVE-2026-105824 · 9h ago
CVE-2026-107209 — ImageMagick is free and open-source software used for editing and manipulating digital images.
CVE-2026-107209 · 1d ago
CVE-2026-107167 — A flaw was found in m17n-lib.
CVE-2026-107167 · 1d ago
CVE-2026-107183 — llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_mapper::map that allows unauthenticated remote a…
CVE-2026-107183 · 1d ago
CVE-2026-55330 — In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code.
CVE-2026-55330 · 2d ago