Use-after-free vulnerability in the O3D plug-in in Google Chrome OS before 26.0.1410.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to improper management of ownership relationships involving Elements and DrawElements.
CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:CGoogle Chrome Os
OSGoogle26.0.1410.026.0.1410.126.0.1410.1026.0.1410.1126.0.1410.1226.0.1410.1426.0.1410.1526.0.1410.1626.0.1410.1726.0.1410.1826.0.1410.1926.0.1410.2026.0.1410.2126.0.1410.2226.0.1410.23+ 39 more
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoS
CWE
References
Related vulnerabilities
CVE-2016-4171CRITICAL9.8⚠ KEVPL ✓same product
RCE w Adobe Flash Player 21.0.0.242 i wcześniejszych — aktywnie exploitowany
CVE-2016-1019CRITICAL9.8⚠ KEVPL ✓same product
Adobe Flash Player — RCE lub DoS przez nieokreślone wektory ataku
CVE-2014-0497CRITICAL9.8⚠ KEVPL ✓same product
Adobe Flash Player — Integer Underflow umożliwiający zdalne wykonanie kodu (RCE)
CVE-2026-17680CRITICAL9.6PL ✓same product
Heap buffer overflow w Color w Google Chrome na ChromeOS — sandbox escape
CVE-2025-6179CRITICAL9.8PL ✓same product
Ominięcie uprawnień w zarządzaniu rozszerzeniami Google ChromeOS