Junglewise Threat Intelligence

CVE-2026-8581: Google Chrome use after free in GPU

CVE-2026-8581 · Severity: high · CVSS 8.8 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its graphics processing component could allow a malicious website to execute unauthorized code on a user's computer. While this code would still be restricted by the browser's security sandbox, it represents a significant risk to user data and system integrity if combined with other flaws.

Technical details

A use-after-free (UAF) vulnerability exists in the GPU component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory lifecycles during graphics processing, allowing a remote attacker to exploit the memory corruption via a crafted HTML page. Successful exploitation enables arbitrary code execution (ACE) within the context of the Chrome sandbox. The vulnerability was addressed in version 148.0.7778.168. Users are advised to update to the latest stable channel release to mitigate this risk.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-05-12: patched: Stable channel update released for Windows, Mac, and Linux.
  • 2026-05-14: disclosed: CVE published to the NVD.

References

Related threats