Junglewise Threat Intelligence

CVE-2026-10988: Google Chrome use after free in Views

CVE-2026-10988 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's 'Views' component, which handles the browser's user interface elements. An attacker could exploit this flaw by tricking a user into visiting a malicious website, potentially allowing the attacker to break out of the browser's security sandbox. If successful, this could lead to full control over the user's computer and unauthorized access to sensitive data.

Technical details

A use-after-free (UAF) vulnerability exists in the Views component of Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the browser incorrectly manages memory for UI elements, allowing an attacker who has already compromised the renderer process to execute arbitrary code outside of the browser's sandbox. This is achieved by enticing a user to load a specially crafted HTML page. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Fixed in version 149.0.7827.53
  • 2026-06-04: disclosed

References

Related threats