Junglewise Threat Intelligence

CVE-2026-8514: Google Chrome use after free in Aura sandbox escape

CVE-2026-8514 · Severity: high · CVSS 8.3 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical vulnerability exists in Google Chrome's Aura component, which handles window management and user interface elements. An attacker who has already compromised a website's rendering process could use this flaw to break out of the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system and the user's private data.

Technical details

A use-after-free (UAF) vulnerability exists in Aura, the window management and graphics shell for Chrome. The flaw is triggered when the browser incorrectly manages the lifecycle of objects within the Aura component. A remote attacker who has already achieved code execution within a compromised renderer process can exploit this memory corruption to escape the Chrome sandbox. This allows for full system compromise or unauthorized access to the host operating system. The vulnerability is addressed in Google Chrome version 148.0.7778.168.

Affected products

  • Google Chrome Prior to 148.0.7778.168

Timeline

  • 2026-03-25: other: Reported to Chrome by Google researchers
  • 2026-05-12: patched: Fixed in Stable Channel Update 148.0.7778.167/168
  • 2026-05-14: disclosed: CVE published to NVD

References

Related threats