Ad

CVE-2026-3777

MEDIUM CVSS 3.1: 5.5 EPSS 0.02%
Updated Apr 01, 2026
Zoom
Parameter Value
CVSS 5.5 (MEDIUM)
Type CWE-416 (Use After Free)
Vendor Zoom
Public PoC No

The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and page state. When a script modifies the zoom property and then triggers a page change, the original view object may be destroyed while stale pointers are still kept and later dereferenced, which under crafted JavaScript and document structures can lead to a use-after-free condition and potentially allow arbitrary code execution.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Weakness Type (CWE)