Junglewise Threat Intelligence

CVE-2026-9951: Google Chrome use after free in UI

CVE-2026-9951 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome web browser could allow a malicious website to bypass security protections. By tricking a user into visiting a specially crafted webpage, an attacker could potentially escape the browser's 'sandbox,' which is designed to keep web code isolated from the rest of the computer. This could lead to unauthorized access to the user's system or data.

Technical details

A use-after-free (UAF) vulnerability exists in the User Interface (UI) component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the lifecycle of UI objects, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious HTML page, a remote attacker can exploit this memory corruption to execute arbitrary code and escape the Chromium sandbox. This vulnerability was addressed in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
  • 2026-05-28: disclosed: CVE published to the NVD.

References

Related threats