Junglewise Threat Intelligence

CVE-2026-9984: Google Chrome use after free in UI

CVE-2026-9984 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Google Chrome web browser on Windows. By tricking a user into visiting a specially crafted website, an attacker could potentially take control of the user's computer or execute unauthorized commands. This could lead to the theft of sensitive data or the installation of malicious software.

Technical details

A use-after-free (UAF) vulnerability exists in the UI component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory for UI elements, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious HTML page, a remote attacker can exploit this condition to achieve arbitrary code execution within the context of the browser process. Google has addressed this issue in version 148.0.7778.216.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for Windows.
  • 2026-05-28: disclosed: CVE published to NVD.

References

Related threats