Junglewise Threat Intelligence

CVE-2026-9894: Google Chrome use after free in GPU

CVE-2026-9894 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in the Google Chrome web browser's graphics processing component. An attacker who has already partially compromised the browser could use this flaw to break out of the security 'sandbox' that normally keeps web content isolated from the rest of the computer. This could allow a malicious website to gain full control over the user's system, potentially leading to data theft or the installation of malware.

Technical details

A use-after-free (UAF) vulnerability exists in the GPU component of Google Chrome. The flaw is reachable by a remote attacker who has already compromised the renderer process. By enticing a user to visit a specially crafted HTML page, the attacker can exploit the memory corruption to achieve a sandbox escape. This allows for code execution outside of the restricted browser environment on the host operating system. The issue is addressed in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop
  • 2026-05-28: disclosed: CVE published to NVD dataset

References

Related threats