Critical severity9.6NVD Advisory· Published Sep 29, 2026· Updated Sep 29, 2026
CVE-2026-95339
CVE-2026-95339
Description
Use after free in ServiceWorker in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
2- ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More ThreatsThe Hacker News · Sep 28, 2026
- Chrome Patches 108 Vulnerabilities Including Crticial Flaws that Enable Code Execution AttacksCyber Security News · Sep 23, 2026