Junglewise Threat Intelligence

CVE-2026-10902: Google Chrome use after free in Ozone

CVE-2026-10902 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A critical security vulnerability was found in its Ozone component, which handles input and graphics across different platforms. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially allowing the attacker to take control of the user's computer or execute unauthorized commands.

Technical details

A use-after-free (UAF) vulnerability exists in the Ozone abstraction layer of Google Chrome. The flaw is triggered when the browser incorrectly manages memory for objects within the Ozone component, which is responsible for platform-specific input and windowing integration. A remote attacker can exploit this by hosting a malicious HTML page that, when rendered by a vulnerable version of Chrome, triggers the memory corruption. This can lead to arbitrary code execution (ACE) within the context of the browser process. The vulnerability is fixed in version 149.0.7827.53 for Linux and 149.0.7827.53/.54 for Windows and Mac.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-05-27: disclosed: Reported to Chromium by Google researchers
  • 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53
  • 2026-06-04: advisory: NVD publication date

References

Related threats