Junglewise Threat Intelligence

CVE-2026-9883: Google Chrome use after free in Base

CVE-2026-9883 · Severity: info · CVSS 9.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser for accessing the internet. A critical vulnerability was found that allows a malicious website to execute unauthorized code on a user's computer if they visit a specially crafted page. This could lead to a complete compromise of the user's system, including the theft of sensitive data or the installation of malware.

Technical details

A use-after-free vulnerability exists in the 'Base' component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of HTML content, allowing a remote attacker to potentially execute arbitrary code in the context of the browser process. An attacker would need to entice a user to visit a malicious website to exploit this vulnerability. The issue is resolved in version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-04-25: disclosed: Reported by Google researchers
  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: advisory: NVD publication date

References

Related threats