Junglewise Threat Intelligence

CVE-2026-9947: Google Chrome use after free in XML

CVE-2026-9947 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its XML processing component could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized actions or be used as part of a larger attack to compromise the system.

Technical details

A use-after-free (UAF) vulnerability exists in the XML parsing component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of XML content within a crafted HTML page. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, leading to arbitrary code execution (ACE) within the context of the browser's sandbox. This vulnerability is tracked as CWE-416. Google has addressed this issue in version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: disclosed: CVE published to NVD

References

Related threats