Junglewise Threat Intelligence

CVE-2026-10886: Google Chrome use after free in FileSystem

CVE-2026-10886 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical vulnerability exists in Google Chrome's FileSystem component that could allow an attacker to escape the browser's security sandbox. By tricking a user into visiting a specially crafted website, an attacker could potentially gain unauthorized access to the underlying operating system. This poses a significant risk to data confidentiality and system integrity, as it bypasses the primary security layer designed to isolate web content from the rest of the computer.

Technical details

This vulnerability is a use-after-free (UAF) class issue (CWE-416) residing within the FileSystem component of the Chromium engine. The flaw is triggered when the browser incorrectly manages memory pointers after an object has been deleted, allowing an attacker to supply a crafted HTML page that exploits this memory corruption. If successfully exploited, a remote, unauthenticated attacker can achieve a sandbox escape, potentially leading to arbitrary code execution on the host system with the privileges of the user running the browser. Google has addressed this in version 149.0.7827.53 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-21: disclosed: Reported by Andrew Boni
  • 2026-06-02: patched: Fixed in version 149.0.7827.53
  • 2026-06-04: advisory: NVD publication date

References

Related threats