Junglewise Threat Intelligence

CVE-2026-10895: Google Chrome use after free in Ozone

CVE-2026-10895 · Severity: info · CVSS 9.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A critical vulnerability was found in its Ozone component, which handles input and graphics. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to take full control of the user's computer or access sensitive data.

Technical details

A use-after-free (UAF) vulnerability exists in the Ozone abstraction layer of Google Chrome. The flaw is triggered when the browser incorrectly manages memory lifecycles during the processing of graphics or input events. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page; when a victim visits the page, the attacker can achieve arbitrary code execution (RCE) within the context of the browser process. This vulnerability was fixed in version 149.0.7827.53 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-05-15: disclosed: Reported by Google internal researchers
  • 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53
  • 2026-06-04: advisory: NVD publication date

References

Related threats