Junglewise Threat Intelligence

CVE-2026-9873: Google Chrome use after free in Network

CVE-2026-9873 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A critical security vulnerability was found in its networking component that could allow a malicious website to execute unauthorized code on a user's computer. While the browser's security 'sandbox' limits the immediate impact, this type of flaw is often used as a stepping stone for more serious attacks on personal data and system stability.

Technical details

A use-after-free (UAF) vulnerability exists in the Network stack of Google Chrome. The flaw is triggered when the browser attempts to use memory that has already been deallocated, specifically during the processing of network-related tasks. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows for arbitrary code execution (ACE) within the context of the Chrome renderer sandbox. The issue is resolved in version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-04-28: other: Reported by researcher cinzinga
  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: disclosed: NVD publication date

References

Related threats