Junglewise Threat Intelligence

CVE-2026-10016: Google Chrome use after free in DOM

CVE-2026-10016 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Google Chrome web browser's Document Object Model (DOM) component. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to execute unauthorized code on the user's computer. While the exploit is contained within the browser's security sandbox, it still poses a significant risk to user data and system integrity.

Technical details

A use-after-free (UAF) vulnerability exists in the Document Object Model (DOM) component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory for DOM objects, allowing an attacker to reference memory after it has been freed. By enticing a user to load a maliciously crafted HTML page, a remote attacker can exploit this condition to achieve arbitrary code execution (ACE) within the browser's sandboxed process. The vulnerability affects Google Chrome versions prior to 148.0.7778.216. Users are advised to update to the latest stable channel release to mitigate this risk.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
  • 2026-05-28: disclosed: CVE published to the NVD.

References

Related threats