VDB

GCVE-110-NCSC-2026-341

GCVE-110-NCSC-2026-341
Advisory PublishedCVSS 3.1/10
Vulnetix · Advisory published September 4, 2026
A use-after-free vulnerability in Google Chrome DevTools before version 152.0.7977.82 allowed remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page, posing a high security risk.

Weaknesses (CWE)

CWE-416Use After FreeCWE-459Incomplete CleanupCWE-672Operation on a Resource after Expiration or ReleaseCWE-367Time-of-check Time-of-use (TOCTOU) Race ConditionCWE-843Access of Resource Using Incompatible Type ('Type Confusion')CWE-787Out-of-bounds WriteCWE-125Out-of-bounds Read

Risk Scores

CVSS 3.1
3.1/10
Low · CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersionsPlatforms
Googlevers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

3,521 records in the GCVE database · Updated September 6, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›