Junglewise Threat Intelligence

CVE-2026-9954: Google Chrome use after free in TabStrip

CVE-2026-9954 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's tab management system could allow a remote attacker to compromise a user's computer. To succeed, an attacker must trick a user into visiting a malicious website and performing specific mouse or keyboard actions within the browser interface. This could lead to unauthorized access to data or the ability to run malicious code on the affected device.

Technical details

A use-after-free (UAF) vulnerability exists in the TabStrip component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during specific user interface gestures, leading to heap corruption. A remote attacker can exploit this by convincing a user to interact with a specially crafted HTML page. If successful, the attacker could achieve arbitrary code execution within the context of the browser process. The issue is addressed in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
  • 2026-05-28: disclosed: CVE published to the NVD.

References

Related threats