Junglewise Threat Intelligence

CVE-2026-9881: Google Chrome use after free in Bluetooth on macOS

CVE-2026-9881 · Severity: info · CVSS 9.6 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome for macOS that could allow a malicious browser extension to bypass security protections. If a user is tricked into installing a specially crafted extension, an attacker could escape the browser's 'sandbox'—the security layer designed to keep web activity isolated from the rest of the computer. This could lead to unauthorized access to the user's files, personal data, or full control over the operating system.

Technical details

A use-after-free (UAF) vulnerability exists in the Bluetooth component of Google Chrome for macOS. The flaw is triggered when a user installs and interacts with a malicious Chrome Extension designed to exploit memory corruption within the browser's Bluetooth handling logic. Successful exploitation allows the attacker to achieve a sandbox escape, moving from the restricted browser process to executing arbitrary code with the privileges of the user on the host operating system. This vulnerability was patched in Chrome version 148.0.7778.216.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-04-22: other: Reported by Google researchers
  • 2026-05-27: patched: Fixed in stable channel update 148.0.7778.216/217
  • 2026-05-28: disclosed: Public advisory published

References

Related threats