CVE-2026-52757
Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::merge() function during the variable mergi
CVSS
4.4
Medio
EPSS
0.1%
p4
KEV
—
Exploit Today
1
0-100
Publicado: 10 jun 2026 · Última mod.: 14 jul 2026 · CWE-416
0.1%EPSS · 30 días0.1%
2026-08-062026-09-02
Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::merge() function during the variable merging pass. Attackers can trigger this vulnerability by crafting a binary that causes stale pointers in the HighIntersectTest::highedgemap cache to be dereferenced, reading and writing the flags field of freed heap memory when a user opens the binary in Ghidra's decompiler view.
- github.comhttps://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-8jqp-qv73-395r
- www.vulncheck.comhttps://www.vulncheck.com/advisories/ghidra-heap-use-after-free-in-highvariable-merge-during-decompilation
- github.comhttps://github.com/NationalSecurityAgency/ghidra/security/advisories/GHSA-8jqp-qv73-395r
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-843539.6 CRÍ19.8%
——6Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)2dCVE-2026-843529.6 CRÍ19.8%
——6Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)2dCVE-2026-843508.8 ALT10.6%
——3Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)2dCVE-2026-843498.3 ALT13.7%
——4Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)2dCVE-2026-843478.8 ALT20.3%
——6Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)2dCVE-2026-843339.6 CRÍ16.1%
——5Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)2d