CVE-2026-10954
Google · Chrome
A use-after-free vulnerability in the Actor component of Google Chrome prior to version 149 may permit an attacker to execute arbitrary code.
Executive summary
A high-severity use-after-free vulnerability in Google Chrome's Actor component presents a significant risk of arbitrary code execution.
Vulnerability
This vulnerability involves a use-after-free condition within the Actor component of the browser. It is triggered when an unauthenticated attacker successfully manipulates memory through a malicious web interaction.
Business impact
The CVSS score of 8.8 highlights the critical nature of this memory corruption flaw. Successful exploitation could lead to full compromise of the browser process, facilitating data theft or further system exploitation.
Remediation
Immediate Action: Apply the latest security updates provided by Google to reach version 149 or greater.
Proactive Monitoring: Audit endpoint security logs for signs of suspicious browser-based process termination or unexpected memory access errors.
Compensating Controls: Ensure that browser-based sandboxing and standard Windows/OS-level security features are enabled and fully patched to provide defense-in-depth.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Promptly patching this vulnerability is essential to maintaining endpoint integrity. Organizations should verify that the update is propagated across all workstations immediately.