Junglewise Threat Intelligence

CVE-2026-10894: Google Chrome use after free in Printing sandbox escape

CVE-2026-10894 · Severity: info · CVSS 9.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in the printing component of Google Chrome for Linux. This flaw could allow a malicious website to bypass the browser's security sandbox, which is designed to keep web content isolated from the rest of the computer. If exploited, an attacker could potentially gain unauthorized access to the underlying operating system, leading to data theft or the installation of malicious software.

Technical details

A use-after-free (UAF) vulnerability exists in the Printing component of Google Chrome for Linux. The flaw is triggered when the browser incorrectly manages memory during printing operations. A remote attacker who has already compromised the renderer process can exploit this issue by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to escape the Chromium security sandbox and execute arbitrary code on the host operating system. This vulnerability was addressed in version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-05-15: disclosed: Reported by Google internal researchers
  • 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53
  • 2026-06-04: advisory: NVD publication date

References

Related threats