Junglewise Threat Intelligence

CVE-2026-9923: Google Chrome use after free in Skia

CVE-2026-9923 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's Skia graphics engine. By tricking a user into visiting a specially crafted website, an attacker could cause the browser to crash or potentially execute unauthorized code on the user's computer. This could lead to the theft of sensitive information or full system compromise.

Technical details

A use-after-free (UAF) vulnerability exists in the Skia graphics component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the rendering of specially crafted HTML content. A remote, unauthenticated attacker can exploit this by hosting a malicious webpage; when a user visits the site, the attacker can trigger heap corruption. This can lead to a browser process crash (Denial of Service) or potentially arbitrary code execution within the context of the browser's sandbox. The issue is resolved in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: disclosed: NVD publication date

References

Related threats