Junglewise Threat Intelligence

CVE-2026-10990: Google Chrome use after free in Glic

CVE-2026-10990 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's Glic component that could allow a malicious website to break out of the browser's security sandbox. If an attacker has already compromised the part of the browser that displays web pages, they could use this flaw to gain broader access to the underlying operating system. This could lead to unauthorized access to local files or the installation of malicious software.

Technical details

A use-after-free (UAF) vulnerability exists in the Glic component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory lifecycle during interactions with Glic, a component within the browser architecture. An attacker who has already achieved code execution within a compromised renderer process can exploit this memory corruption to bypass the Chrome sandbox. This attack is typically delivered via a specially crafted HTML page. Successful exploitation allows the attacker to escape the restricted renderer environment and execute arbitrary code with the privileges of the browser process on the host operating system. The issue is resolved in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-10990 published.

References

Related threats