Junglewise Threat Intelligence

CVE-2026-10918: Google Chrome use after free in Viz

CVE-2026-10918 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics compositing component (Viz) could allow an attacker to bypass the browser's security sandbox. If a user visits a malicious website, an attacker who has already compromised the browser's rendering process could gain broader access to the underlying operating system. This could lead to unauthorized data access or the ability to execute malicious code outside the restricted browser environment.

Technical details

A use-after-free (UAF) vulnerability exists in the Viz (Visuals) component of Google Chrome. The flaw is triggered when the browser improperly manages memory during the processing of graphics or layout information. An attacker who has already achieved code execution within the sandboxed renderer process (e.g., via a separate V8 or DOM vulnerability) can exploit this UAF to escape the sandbox and execute arbitrary code with the privileges of the browser process. This requires the victim to navigate to a specially crafted HTML page. The issue is resolved in Chrome version 149.0.7827.53 and later.

Affected products

  • Google Chrome Prior to 149.0.7827.53

Timeline

  • 2026-03-31: disclosed: Reported by Google internal researchers
  • 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53
  • 2026-06-04: advisory: NVD publication date

References

Related threats