Junglewise Threat Intelligence

CVE-2026-10908: Google Chrome use after free in FullScreen

CVE-2026-10908 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's FullScreen component on Windows. An attacker could use a specially crafted website to break out of the browser's security sandbox, potentially gaining unauthorized access to the underlying operating system. This could lead to the theft of sensitive data or the installation of malicious software on the user's computer.

Technical details

A use-after-free (UAF) vulnerability exists in the FullScreen component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during transitions to or from full-screen mode. An attacker who has already compromised the renderer process can exploit this condition via a crafted HTML page to achieve a sandbox escape, leading to arbitrary code execution on the host system. This vulnerability was addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-21: disclosed: Reported by Mihnea Nicolau
  • 2026-06-02: patched: Fixed in version 149.0.7827.53/54
  • 2026-06-04: advisory

References

Related threats