Junglewise Threat Intelligence

CVE-2026-9970: Google Chrome use after free in WebGL

CVE-2026-9970 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Chrome's WebGL component, which is used for rendering 3D graphics in the browser. If an attacker has already compromised a user's browser tab, they could use this flaw to break out of the browser's security sandbox. This could allow them to gain unauthorized access to the underlying operating system and sensitive user data.

Technical details

A use-after-free (UAF) vulnerability exists in the WebGL component of Google Chrome (CWE-416). The flaw is reachable via a specially crafted HTML page. An attacker who has already achieved code execution within the sandboxed renderer process can exploit this memory corruption issue to bypass the sandbox boundary. This allows for a full sandbox escape, potentially leading to arbitrary code execution on the host operating system. The issue is resolved in Google Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop
  • 2026-05-28: disclosed: CVE published to NVD

References

Related threats