CVE-2026-76021: Use after free in DOM
Chromium CVE-2026-76021: Use after free in DOM
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.7922.173 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.4129.107 - Upgrade
Upgrade
Google Chrome / Chromium-based browsersto a version that resolves this vulnerability.Fixed in 151.0.7922.173
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
Which software is identified as affected?
The available data identifies Google Chrome from Google. It does not provide affected or fixed version numbers.
What temporary mitigation is documented if an update cannot be applied immediately?
No temporary mitigation or configuration workaround is provided in the available data.
How can I determine whether a system is affected?
The available data does not include affected-version criteria, detection guidance, or indicators of compromise.