Junglewise Threat Intelligence

CVE-2026-9112: Google Chrome use after free in GPU

CVE-2026-9112 · Severity: high · CVSS 8.8 · Published 2026-05-20

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Google Chrome web browser on Windows. By tricking a user into visiting a specially crafted website, an attacker could execute malicious code on the user's computer. While the code is restricted by the browser's security sandbox, this could still lead to unauthorized access to data or serve as a stepping stone for further attacks.

Technical details

A use-after-free (UAF) vulnerability exists in the GPU component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during the processing of GPU-related tasks, allowing an attacker to reference memory after it has been freed. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious HTML page. Successful exploitation allows for arbitrary code execution within the context of the Chrome sandbox. The issue is resolved in version 148.0.7778.179 for Windows.

Affected products

  • Google Chrome Prior to 148.0.7778.179 on Windows

Timeline

  • 2026-03-05: other: Reported by external researcher
  • 2026-05-19: patched: Stable channel update released
  • 2026-05-20: disclosed: CVE published

References

Related threats