Sandbox escape due to use-after-free in the DOM: Core & HTML component (CVE-2026-100811) | HOL Guard CVE