Junglewise Threat Intelligence

CVE-2026-8549: Google Chrome use after free in Media

CVE-2026-8549 · Severity: high · CVSS 8.8 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's media handling component could allow an attacker to execute malicious code on a user's computer. This occurs when a user visits a specially crafted website, potentially leading to unauthorized access to browser data or a compromise of the application's security boundaries. Users are advised to update their browser to the latest version to mitigate this risk.

Technical details

A use-after-free (UAF) vulnerability exists in the Media component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of media content within a crafted HTML page. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, leading to memory corruption. Successful exploitation allows for arbitrary code execution within the context of the Chrome sandbox. The issue is resolved in version 148.0.7778.168 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-03-31: other: Reported to Chrome by Google researchers
  • 2026-05-12: patched: Fixed in Chrome version 148.0.7778.168
  • 2026-05-14: disclosed: Public CVE publication

References

Related threats