Junglewise Threat Intelligence

CVE-2026-9891: Google Chrome use after free in Extensions

CVE-2026-9891 · Severity: info · CVSS 9.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome's extension system. This flaw could allow a malicious actor who has already gained a foothold in the browser to break out of the security sandbox, potentially gaining full control over the underlying operating system. Users are advised to update to the latest version of Chrome to mitigate this risk.

Technical details

A use-after-free (UAF) vulnerability exists within the Extensions component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the execution of extension-related tasks. An attacker who has already achieved remote code execution within a compromised renderer process can leverage this vulnerability via a specially crafted Chrome Extension to bypass the browser's sandbox. Successful exploitation allows the attacker to escape the restricted environment and execute arbitrary code with the privileges of the browser process on the host operating system. The issue is resolved in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop.
  • 2026-05-28: disclosed: CVE published to NVD.

References

Related threats