Junglewise Threat Intelligence

CVE-2026-10956: Google Chrome use after free in MimeHandlerView

CVE-2026-10956 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's MimeHandlerView component, which handles how certain file types are displayed in the browser. By tricking a user into visiting a specially crafted website, an attacker could execute malicious code on the user's computer. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized data access or further system compromise.

Technical details

A use-after-free (UAF) vulnerability exists in the MimeHandlerView component of Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the browser incorrectly manages memory during the rendering of specific content, allowing an attacker to reference memory after it has been freed. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious HTML page. Successful exploitation allows for arbitrary code execution (ACE) within the context of the browser's sandboxed process. Users are advised to update to version 149.0.7827.53 or later to mitigate this risk.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-10956 published.

References

Related threats