Junglewise Threat Intelligence

CVE-2026-8551: Google Chrome use after free in Downloads

CVE-2026-8551 · Severity: high · CVSS 8.8 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Downloads component of Google Chrome could allow a remote attacker to execute malicious code on a user's computer. To exploit this, an attacker must trick a user into visiting a specially crafted website and performing specific interactions or gestures within the browser's interface. Successful exploitation could lead to a full system compromise, unauthorized data access, or the installation of malware.

Technical details

A use-after-free (UAF) vulnerability exists in the Downloads component of Google Chrome prior to version 148.0.7778.168. The flaw is triggered when the browser incorrectly manages memory during download operations, specifically when a user is coerced into performing certain UI gestures on a malicious HTML page. This memory corruption allows a remote attacker to achieve arbitrary code execution (ACE) within the context of the browser process. The vulnerability is tracked as CWE-416 and was resolved in the Stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome Prior to 148.0.7778.168

Timeline

  • 2026-04-01: other: Reported to Chrome by Google researchers
  • 2026-05-12: patched: Fixed in Chrome version 148.0.7778.168
  • 2026-05-14: disclosed: NVD publication date

References

Related threats