Junglewise Threat Intelligence

CVE-2026-8574: Google Chrome use after free in Core component

CVE-2026-8574 · Severity: high · CVSS 8.3 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Windows could allow an attacker to bypass the browser's security sandbox. This occurs when a user visits a specially crafted website, potentially allowing the attacker to gain control over the underlying operating system. This could lead to unauthorized access to local files, installation of malicious software, or full system compromise.

Technical details

A use-after-free vulnerability exists in the 'Core' component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during the processing of crafted HTML content. An attacker who has already compromised the renderer process can exploit this memory corruption to escape the Chrome sandbox and execute arbitrary code on the host operating system. The vulnerability is addressed in version 148.0.7778.168 for Windows.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-05-12: patched: Stable channel update released for desktop.
  • 2026-05-14: disclosed: CVE published to NVD.

References

Related threats