CVE-2026-102324: Use After Free
Published Sep 29, 2026
·Updated
Use after free in PictureInPicture in Google Chrome prior to 154.0.8037.92 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Affected Software
1 affected component
Google Chrome<154.0.8037.92
Event History
Sep 29, 2026
CVE Published
via MITRE·07:45 PM
Data Sourced
via MITRE·07:45 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need before this issue can be used?
The attacker must first have compromised the Chrome renderer process. The issue can then potentially be used to execute arbitrary code outside the sandbox through a crafted HTML page.
2
Which Chrome versions need to be remediated?
Google Chrome versions prior to 154.0.8037.92 are affected. Update Chrome to 154.0.8037.92 or later.