Junglewise Threat Intelligence

CVE-2026-9933: Google Chrome use after free in Input

CVE-2026-9933 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's input handling could allow a remote attacker to compromise a user's computer. By tricking a user into visiting a malicious website and performing specific mouse or keyboard actions, an attacker could potentially execute unauthorized code or crash the browser. This could lead to the theft of sensitive personal information or a complete takeover of the user's browsing session.

Technical details

A use-after-free (UAF) vulnerability exists in the Input component of Google Chrome prior to version 148.0.7778.216. The flaw is triggered when the browser incorrectly manages memory during the processing of specific user interface gestures. A remote attacker can exploit this by hosting a specially crafted HTML page; if a user visits the page and performs the required UI actions, the attacker can trigger heap corruption. This can lead to arbitrary code execution within the context of the browser renderer process. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop versions.
  • 2026-05-28: disclosed: CVE published to NVD.

References

Related threats