Junglewise Threat Intelligence

CVE-2026-8533: Google Chrome use after free in Accessibility

CVE-2026-8533 · Severity: high · CVSS 8.3 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's accessibility features could allow an attacker to bypass the browser's security sandbox. This occurs if a user visits a specially crafted malicious website. If successful, an attacker who has already gained limited control over the browser's rendering process could escalate their access to the underlying operating system, potentially leading to unauthorized data access or full system compromise.

Technical details

A use-after-free (UAF) vulnerability exists in the Accessibility component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory for accessibility objects, allowing an attacker to reference memory after it has been freed. To exploit this, a remote attacker must first compromise the renderer process (e.g., via a separate vulnerability) and then use a crafted HTML page to trigger the UAF condition. Successful exploitation allows the attacker to escape the Chrome sandbox and execute arbitrary code on the host system. The vulnerability is fixed in version 148.0.7778.168.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-03-23: disclosed: Reported by Google researchers
  • 2026-05-12: patched: Fixed in Stable channel update 148.0.7778.168
  • 2026-05-14: advisory: NVD publication date

References

Related threats