Junglewise Threat Intelligence

CVE-2026-9884: Google Chrome use after free in Browser on Mac

CVE-2026-9884 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A critical security vulnerability has been identified in the Mac version that could allow a malicious website to execute unauthorized code on a user's computer. This could lead to the theft of sensitive data, installation of malware, or full system compromise if a user visits a specially crafted webpage.

Technical details

A use-after-free (CWE-416) vulnerability exists in the Browser component of Google Chrome on macOS. The flaw is triggered when the browser attempts to access memory that has already been freed, typically during the processing of specifically crafted HTML content. A remote attacker can exploit this by enticing a user to visit a malicious website, leading to arbitrary code execution (RCE) within the context of the browser process. The vulnerability is addressed in version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-04-30: disclosed: Reported by Google internal researchers
  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: advisory: NVD publication date

References

Related threats