Junglewise Threat Intelligence

CVE-2026-8542: Google Chrome use after free in Core component

CVE-2026-8542 · Severity: high · CVSS 8.3 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Windows is a web browser used to access the internet and run web applications. A vulnerability in the browser's core components could allow a malicious website to bypass security protections known as the 'sandbox.' If successful, an attacker who has already gained a foothold in the browser could take control of the underlying Windows operating system, potentially leading to data theft or the installation of malware.

Technical details

A use-after-free (UAF) vulnerability exists in the 'Core' component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory lifecycles, allowing a remote attacker to exploit a memory corruption state. To successfully exploit this, an attacker must first compromise the renderer process (typically via a separate vulnerability) and then entice a user to visit a specially crafted HTML page. This chain allows the attacker to perform a sandbox escape, moving from the restricted browser process to the broader host operating system. The issue is resolved in version 148.0.7778.168.

Affected products

  • Google Chrome Prior to 148.0.7778.168 on Windows

Timeline

  • 2026-03-28: disclosed: Reported to Chromium by Google researchers
  • 2026-05-12: patched: Fixed in Stable Channel Update 148.0.7778.168 for Windows
  • 2026-05-14: advisory: NVD publication date

References

Related threats