Junglewise Threat Intelligence

CVE-2026-10959: Google Chrome for Android use after free in Input

CVE-2026-10959 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Chrome for Android, a widely used mobile web browser. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website. If successful, the attacker could execute malicious code on the device, potentially leading to the theft of sensitive information or unauthorized access to browser data, though the impact is limited by the browser's security sandbox.

Technical details

A use-after-free (UAF) vulnerability exists in the Input component of Google Chrome for Android. The flaw is triggered when the browser incorrectly manages memory during the processing of user input events. A remote, unauthenticated attacker can exploit this by inducing a user to visit a malicious HTML page, leading to memory corruption. This allows for arbitrary code execution (ACE) within the context of the browser's sandboxed process. The issue is resolved in version 149.0.7827.53 and later.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 promoted to stable channel
  • 2026-06-04: disclosed: NVD publication date

References

Related threats