Junglewise Threat Intelligence

CVE-2026-9992: Google Chrome use after free in Network

CVE-2026-9992 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its networking component could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized actions or be used as part of a larger attack to compromise the system.

Technical details

A use-after-free vulnerability exists in the Network component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during network operations, which can be exploited by a remote attacker who convinces a user to visit a malicious HTML page. Successful exploitation allows for arbitrary code execution within the context of the Chrome sandbox. Google has addressed this issue in version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop
  • 2026-05-28: disclosed: CVE published to NVD

References

Related threats