Junglewise Threat Intelligence

CVE-2026-9887: Google Chrome use after free in Proxy

CVE-2026-9887 · Severity: info · CVSS 9.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical vulnerability has been identified in the Google Chrome web browser's proxy handling component. By convincing a user to use a specially crafted Proxy Auto-Config (PAC) script, a remote attacker could execute malicious code on the user's computer. This could lead to a total compromise of the affected system, including the theft of sensitive data or the installation of malware.

Technical details

A use-after-free vulnerability exists in the Proxy component of Google Chrome. The flaw is triggered when the browser processes a maliciously crafted Proxy Auto-Config (PAC) script. An attacker can exploit this memory corruption vulnerability to achieve remote code execution (RCE) within the context of the browser process. The vulnerability is resolved in version 148.0.7778.216 and later. While the advisory lists the severity as 'info' in some metadata, Chromium's internal assessment classifies this as 'Critical' due to the potential for arbitrary code execution.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for Desktop
  • 2026-05-28: disclosed: CVE published to NVD dataset

References

Related threats