Junglewise Threat Intelligence

CVE-2026-8530: Google Chrome use after free in Network component

CVE-2026-8530 · Severity: high · CVSS 8.3 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome web browser on Windows could allow a remote attacker to bypass security protections. By convincing a user to visit a specially crafted website, an attacker who has already partially compromised the browser's rendering process could escape the 'sandbox'—a security layer designed to keep malicious code from affecting the rest of the computer. This could lead to full control over the user's system and unauthorized access to sensitive data.

Technical details

A use-after-free (UAF) vulnerability exists in the Network component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during network operations, allowing a remote attacker to exploit the memory corruption. To achieve a full sandbox escape, the attacker must first have compromised the renderer process (e.g., via a separate vulnerability). By enticing a user to load a malicious HTML page, the attacker can leverage this UAF to execute code outside of the restricted sandbox environment. The issue is addressed in Google Chrome version 148.0.7778.168.

Affected products

  • Google Chrome Prior to 148.0.7778.168

Timeline

  • 2026-03-11: other: Reported to Google by internal researchers
  • 2026-05-12: patched: Fixed in stable channel update 148.0.7778.168
  • 2026-05-14: disclosed: CVE published to NVD

References

Related threats