Junglewise Threat Intelligence

CVE-2026-9118: Google Chrome use after free in XR

CVE-2026-9118 · Severity: high · CVSS 8.8 · Published 2026-05-20

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's Extended Reality (XR) component on Windows. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to take control of the user's computer or execute unauthorized commands. This could lead to the theft of sensitive data or a complete compromise of the affected system.

Technical details

A use-after-free (UAF) vulnerability exists in the XR (Extended Reality) component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during the processing of XR-related content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious HTML page. Successful exploitation allows for arbitrary code execution (ACE) within the context of the browser process. Google has addressed this issue in version 148.0.7778.179 for Windows.

Affected products

  • Google Chrome Prior to 148.0.7778.179

Timeline

  • 2026-04-14: other: Reported to Google
  • 2026-05-19: patched: Stable channel update released
  • 2026-05-20: advisory: NVD publication date

References

Related threats