Junglewise Threat Intelligence

CVE-2026-8523: Google Chrome use after free in Mojo

CVE-2026-8523 · Severity: high · CVSS 8.3 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Mojo communication framework could allow an attacker to bypass security boundaries. If a user visits a malicious website, an attacker who has already compromised the browser's rendering process can escape the 'sandbox'—a security layer designed to keep web threats from reaching the rest of the computer. This could lead to unauthorized access to the underlying operating system and user data.

Technical details

A use-after-free (UAF) vulnerability exists in Mojo, the inter-process communication (IPC) framework used in Google Chrome. The flaw is triggered when the browser incorrectly manages the lifecycle of objects within Mojo, allowing a remote attacker to reference memory after it has been freed. To exploit this, an attacker must first compromise the renderer process (typically via a separate vulnerability) and then use a crafted HTML page to trigger the UAF. Successful exploitation allows the attacker to escape the Chrome sandbox and execute arbitrary code with the privileges of the browser process. The issue is resolved in Google Chrome version 148.0.7778.168.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-02-12: disclosed: Reported by Paul Seekamp / nullenc0de
  • 2026-05-12: patched: Fixed in Stable Channel Update 148.0.7778.167/168
  • 2026-05-14: advisory: NVD publication date

References

Related threats