Junglewise Threat Intelligence

CVE-2026-9886: Google Chrome use after free in Base component on macOS

CVE-2026-9886 · Severity: info · CVSS 9.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome for macOS that could allow an attacker to bypass the browser's security sandbox. By tricking a user into visiting a specially crafted website, a remote attacker could potentially gain unauthorized access to the underlying operating system. This could lead to full system compromise, data theft, or the installation of malicious software.

Technical details

A use-after-free (UAF) vulnerability exists in the 'Base' component of Google Chrome for macOS. The flaw is triggered when the browser improperly manages memory during the processing of specifically crafted HTML content. A remote, unauthenticated attacker can exploit this by inducing a user to visit a malicious webpage, leading to memory corruption. This corruption can be leveraged to escape the Chrome sandbox environment and execute arbitrary code with the privileges of the logged-in user on the host operating system. The vulnerability is addressed in Chrome version 148.0.7778.216 for Mac.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Fixed in version 148.0.7778.216/217
  • 2026-05-28: disclosed: NVD publication date

References

Related threats