Junglewise Threat Intelligence

CVE-2026-9936: Google Chrome use after free in GFX on macOS

CVE-2026-9936 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome for macOS could allow a malicious website to bypass the browser's security sandbox. This sandbox is designed to prevent malicious code from interacting with the rest of the computer. If successfully exploited, an attacker who has already gained a foothold in the browser's rendering process could potentially gain broader access to the underlying operating system.

Technical details

A use-after-free (UAF) vulnerability exists in the GFX component of Google Chrome for macOS. The flaw is triggered when the browser incorrectly manages memory during the processing of graphics-related tasks. An attacker who has already compromised the renderer process (for example, via a separate vulnerability) can exploit this issue by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to escape the Chrome sandbox and execute arbitrary code with the privileges of the browser process. This issue was addressed in version 148.0.7778.216.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Fixed in Stable Channel Update 148.0.7778.216/217
  • 2026-05-28: disclosed

References

Related threats