Junglewise Threat Intelligence

CVE-2026-9952: Google Chrome use after free in WebAudio

CVE-2026-9952 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's WebAudio component, which handles audio processing in the browser. By tricking a user into visiting a specially crafted website, an attacker could execute malicious code on the user's computer. While the code is restricted by the browser's security sandbox, this flaw could lead to data theft or further system compromise if combined with other vulnerabilities.

Technical details

A use-after-free (UAF) vulnerability exists in the WebAudio implementation of Google Chrome. The flaw is triggered when the browser incorrectly manages memory for audio objects, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious website, a remote attacker can exploit this condition via a crafted HTML page to achieve arbitrary code execution within the browser's sandbox. The vulnerability is addressed in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop
  • 2026-05-28: disclosed: NVD publication date

References

Related threats