Junglewise Threat Intelligence

CVE-2026-9922: Google Chrome use after free in GPU on Mac

CVE-2026-9922 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Google Chrome web browser for Mac. This flaw allows a malicious website to potentially take control of a user's computer if the browser's internal security layers have already been partially bypassed. Exploitation could lead to unauthorized access to personal data, installation of malware, or complete system compromise.

Technical details

A use-after-free (UAF) vulnerability exists in the GPU component of Google Chrome for Mac. The flaw is triggered when the browser incorrectly manages memory during the processing of graphics-related tasks. An attacker who has already achieved code execution within the sandboxed renderer process can leverage this vulnerability to escape the sandbox and execute arbitrary code with the privileges of the GPU process. This is typically achieved by enticing a user to visit a specially crafted HTML page. The issue is resolved in Chrome version 148.0.7778.216 for Mac.

Affected products

  • Google Chrome Prior to 148.0.7778.216 on Mac

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop
  • 2026-05-28: disclosed: NVD publication date

References

Related threats