Junglewise Threat Intelligence

CVE-2026-10933: Google Chrome use after free in Audio component

CVE-2026-10933 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the audio component of Google Chrome for Windows. This flaw could allow a malicious website to break out of the browser's security sandbox, potentially giving an attacker control over the underlying computer system. Users should update to the latest version of Chrome to protect their data and operations.

Technical details

A use-after-free (UAF) vulnerability exists in the Audio component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during audio processing. A remote attacker who has already compromised the renderer process can exploit this issue by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to escape the Chrome sandbox and execute arbitrary code with the privileges of the browser process. This issue is resolved in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-11: disclosed: Reported to Chromium project
  • 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53
  • 2026-06-04: advisory: NVD publication date

References

Related threats