Junglewise Threat Intelligence

CVE-2026-9905: Google Chrome use after free in Accessibility

CVE-2026-9905 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's accessibility features on Windows. If a user visits a malicious website, an attacker who has already partially compromised the browser could use this flaw to break out of the security 'sandbox' that normally isolates web pages from the rest of the computer. This could allow the attacker to gain broader access to the user's system and data.

Technical details

A use-after-free (UAF) vulnerability exists in the Accessibility component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory for accessibility objects, allowing an attacker to reference memory after it has been freed. To exploit this, an attacker must first compromise the renderer process (typically via a separate vulnerability). Once the renderer is compromised, the attacker can use a specially crafted HTML page to trigger the UAF and achieve a sandbox escape, potentially leading to full system compromise. This issue was addressed in Chrome version 148.0.7778.216.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
  • 2026-05-28: disclosed: CVE published to the NVD.

References

Related threats