Junglewise Threat Intelligence

CVE-2026-10982: Google Chrome use after free in WebXR

CVE-2026-10982 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its WebXR component, which handles virtual and augmented reality content, could allow an attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized actions or be combined with other flaws to compromise the entire system.

Technical details

A use-after-free (UAF) vulnerability exists in the WebXR implementation of Google Chrome. The flaw is triggered when the browser incorrectly manages memory for objects used in virtual or augmented reality sessions, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious website, a remote attacker can exploit this condition to achieve arbitrary code execution (ACE) within the context of the Chromium sandbox. The vulnerability is addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published in NVD

References

Related threats