Junglewise Threat Intelligence

CVE-2026-8512: Google Chrome use after free in FileSystem

CVE-2026-8512 · Severity: high · CVSS 8.3 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's FileSystem component, which handles how the browser interacts with files. An attacker could exploit this by tricking a user into performing specific mouse or keyboard actions on a malicious website. If successful, the attacker could bypass the browser's security 'sandbox,' potentially allowing them to gain unauthorized access to the underlying operating system or user data.

Technical details

A use-after-free (UAF) vulnerability exists in the FileSystem component of Google Chrome prior to version 148.0.7778.168. The flaw is triggered when the browser incorrectly manages memory for file system objects, allowing an attacker to reuse memory after it has been freed. To exploit this, a remote attacker must convince a user to visit a specially crafted HTML page and perform specific UI gestures. Successful exploitation can lead to a sandbox escape, allowing the attacker to execute arbitrary code outside the restricted browser environment. Google has addressed this in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-03-24: other: Reported by Google researchers
  • 2026-05-12: patched: Fixed in version 148.0.7778.168
  • 2026-05-14: disclosed: Public advisory published

References

Related threats