Junglewise Threat Intelligence

CVE-2026-8580: Google Chrome use after free in Mojo

CVE-2026-8580 · Severity: critical · CVSS 9.6 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Mojo component could allow a malicious website to break out of the browser's security sandbox. This could allow an attacker to gain unauthorized access to the underlying operating system and user data. Users are protected by updating to the latest version of the Chrome browser.

Technical details

A use-after-free (UAF) vulnerability exists in the Mojo IPC framework within Google Chrome. The flaw is triggered when the browser improperly handles object lifecycles during communication between different browser processes. By enticing a user to visit a specially crafted HTML page, a remote attacker can exploit this memory corruption to execute arbitrary code and escape the Chrome sandbox. This vulnerability was addressed in Chrome version 148.0.7778.168 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-05-12: patched: Chrome Stable Channel Update released version 148.0.7778.167/168
  • 2026-05-14: disclosed: CVE-2026-8580 published

References

Related threats