Junglewise Threat Intelligence

CVE-2026-10957: Google Chrome use after free in Glic

CVE-2026-10957 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's Glic component that could allow a malicious website to execute unauthorized code on a user's computer. While the exploit is contained within the browser's security sandbox, it represents a significant risk to user privacy and system integrity if combined with other flaws. Users are protected by updating to the latest version of the Chrome browser.

Technical details

A use-after-free (UAF) vulnerability exists in the Glic component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of a crafted HTML page, allowing a remote attacker to achieve arbitrary code execution (ACE) within the confines of the browser's sandbox. The vulnerability is classified as High severity by Chromium. It was addressed in Google Chrome version 149.0.7827.53 for Windows, Mac, and Linux. Exploitation requires a user to visit a malicious website.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-10957 published.

References

Related threats