Junglewise Threat Intelligence

CVE-2026-9897: Google Chrome use after free in DOM

CVE-2026-9897 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in how the browser handles website components (the DOM) could allow a malicious website to execute unauthorized code on a user's computer. While this code is restricted to a 'sandbox' environment, it represents a significant security risk that could lead to further system compromise if combined with other flaws.

Technical details

A use-after-free (UAF) vulnerability exists in the Document Object Model (DOM) component of Google Chrome. The flaw is triggered when the browser attempts to access memory that has already been deallocated during the processing of HTML content. A remote attacker can exploit this by enticing a user to visit a maliciously crafted website, leading to arbitrary code execution within the browser's sandbox. This vulnerability is addressed in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
  • 2026-05-28: disclosed: CVE published to NVD.

References

Related threats