Junglewise Threat Intelligence

CVE-2026-8522: Google Chrome use after free in Downloads on macOS

CVE-2026-8522 · Severity: high · CVSS 8.8 · Published 2026-05-14

Technologies: Apple macOS, Google Chrome. Vendors: Apple, Google.

Executive brief

A critical security vulnerability exists in the Google Chrome web browser for macOS. By tricking a user into visiting a specially crafted website, an attacker could potentially take control of the user's computer or execute unauthorized commands. This issue specifically affects the browser's download management component and could lead to data theft or system compromise.

Technical details

A use-after-free (UAF) vulnerability exists in the Downloads component of Google Chrome for macOS. The flaw is triggered when the browser incorrectly manages memory during download operations, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious HTML page, a remote attacker can exploit this memory corruption to achieve arbitrary code execution (RCE) within the context of the browser process. This vulnerability was addressed in version 148.0.7778.168.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-04-19: disclosed: Reported to Chromium by Google researchers
  • 2026-05-12: patched: Stable channel update released for Mac
  • 2026-05-14: advisory: NVD publication date

References

Related threats