Junglewise Threat Intelligence

CVE-2026-10005: Google Chrome use after free in WebAppInstalls on macOS

CVE-2026-10005 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome for macOS that could allow a malicious website to take control of a user's computer. By tricking a user into performing specific mouse or keyboard actions on a specially crafted webpage, an attacker can execute unauthorized code. This could lead to the theft of sensitive data, installation of malware, or full system compromise.

Technical details

A use-after-free (UAF) vulnerability exists in the WebAppInstalls component of Google Chrome for macOS. The flaw is triggered when the browser incorrectly manages memory during the installation or handling of web applications. A remote attacker can exploit this by hosting a malicious HTML page and enticing a user to perform specific UI gestures (user interaction). Successful exploitation allows the attacker to corrupt memory and achieve arbitrary code execution within the context of the browser process. This issue was addressed in Chrome version 148.0.7778.216.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for macOS
  • 2026-05-28: disclosed: CVE published to NVD dataset

References

Related threats