Junglewise Threat Intelligence

CVE-2026-9964: Google Chrome use after free in Bluetooth on Mac

CVE-2026-9964 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome for Mac could allow a malicious browser extension to take control of a user's computer. If a user is tricked into installing a specifically crafted extension, an attacker could execute arbitrary commands and access sensitive data. This issue affects the Bluetooth component of the browser on macOS systems.

Technical details

A use-after-free (UAF) vulnerability exists in the Bluetooth implementation of Google Chrome for macOS (CWE-416). The flaw is triggered when the browser incorrectly manages memory during Bluetooth operations, which can be exploited by a malicious Chrome Extension. An attacker who successfully convinces a user to install a crafted extension can leverage this memory corruption to execute arbitrary code with the privileges of the browser process. The vulnerability was addressed in Chrome version 148.0.7778.216 for Mac.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop
  • 2026-05-28: disclosed: CVE published to NVD

References

Related threats