Junglewise Threat Intelligence

CVE-2026-10882: Google Chrome use after free in Network

CVE-2026-10882 · Severity: info · CVSS 9.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical vulnerability exists in the Google Chrome web browser's networking component. By tricking a user into visiting a specially crafted website, a remote attacker could gain full control over the user's computer. This could lead to the theft of sensitive data, installation of malware, or complete system compromise.

Technical details

A use-after-free (UAF) vulnerability exists in the Network stack of Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the browser incorrectly manages memory during the processing of network requests or responses. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page and enticing a user to visit it. Successful exploitation allows the attacker to bypass memory safety protections and execute arbitrary code within the context of the browser process. Google has addressed this in the stable channel update to version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-17: disclosed: Reported by external researcher
  • 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable channel update
  • 2026-06-04: advisory: NVD publication date

References

Related threats