Junglewise Threat Intelligence

CVE-2026-10003: Google Chrome use after free in Views

CVE-2026-10003 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in the browser's user interface component could allow a remote attacker to execute malicious code on a user's computer. To succeed, an attacker must trick a user into visiting a specially crafted website and performing specific mouse or keyboard actions, potentially leading to full system compromise or data theft.

Technical details

A use-after-free (UAF) vulnerability exists in the 'Views' component of Google Chrome prior to version 148.0.7778.216. The flaw is triggered when a user interacts with a specially crafted HTML page using specific UI gestures, leading to memory corruption. A remote attacker can exploit this to achieve arbitrary code execution within the context of the browser process. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: disclosed: NVD publication date

References

Related threats