Junglewise Threat Intelligence

CVE-2026-10972: Google Chrome Use After Free in Ozone on Linux

CVE-2026-10972 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Linux could allow a malicious website to bypass the browser's security sandbox. This sandbox is designed to isolate web pages from the rest of the computer to prevent malicious code from accessing private files or taking control of the operating system. If exploited, an attacker could potentially gain unauthorized access to the underlying system after a user visits a specially crafted webpage.

Technical details

A use-after-free (UAF) vulnerability exists in the Ozone abstraction layer of Google Chrome for Linux. Ozone is the windowing system abstraction layer used by Chromium. The flaw is triggered when the browser incorrectly manages memory lifecycle for objects within this component, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a specially crafted HTML page, a remote attacker can exploit this memory corruption to execute arbitrary code and escape the Chrome sandbox. This vulnerability was addressed in version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 for Linux
  • 2026-06-04: disclosed: NVD publication date

References

Related threats