Junglewise Threat Intelligence

CVE-2026-10995: Google Chrome heap buffer overflow in TabStrip

CVE-2026-10995 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's tab management interface could allow a malicious website to cause the browser to crash or behave unexpectedly. To trigger the issue, an attacker must trick a user into visiting a specially crafted webpage and performing specific mouse or keyboard actions within the browser interface. While primarily affecting stability, such flaws can sometimes be used as a stepping stone for more complex attacks.

Technical details

A heap buffer overflow vulnerability exists in the TabStrip component of Google Chrome prior to version 149.0.7827.53. The flaw is triggered when a remote attacker convinces a user to visit a crafted HTML page and perform specific UI gestures, leading to heap corruption. This is classified as a CWE-122 (Heap-based Buffer Overflow). Successful exploitation could allow an attacker to cause a denial-of-service (browser crash) or potentially achieve arbitrary code execution within the context of the browser process, though the latter typically requires bypassing additional sandbox protections. The issue was addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome Prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-10995 published.

References

Related threats