Junglewise Threat Intelligence

CVE-2026-9893: Google Chrome use after free in Skia

CVE-2026-9893 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical vulnerability in Google Chrome's Skia graphics engine could allow an attacker to bypass security protections. If a user visits a specially crafted website, an attacker who has already compromised the browser's rendering process could escape the 'sandbox'—the security layer designed to isolate the browser from the rest of the computer. This could lead to unauthorized access to the underlying operating system and sensitive user data.

Technical details

A use-after-free (UAF) vulnerability exists in the Skia graphics component of Google Chrome. The flaw is reachable via a crafted HTML page. An attacker who has already achieved code execution within the sandboxed renderer process can exploit this memory corruption issue to perform a sandbox escape, potentially gaining full execution privileges on the host operating system. The vulnerability is addressed in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
  • 2026-05-28: disclosed: CVE published to the NVD.

References

Related threats