Junglewise Threat Intelligence

CVE-2026-9993: Google Chrome use after free in Views

CVE-2026-9993 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's user interface component could allow a malicious actor to bypass the browser's security sandbox. This occurs when a user opens a specially crafted PDF file, potentially allowing an attacker who has already compromised a browser tab to gain broader access to the underlying computer system. This could lead to unauthorized data access or the execution of malicious software outside of the browser's restricted environment.

Technical details

A use-after-free (UAF) vulnerability exists in the 'Views' component of Google Chrome. The flaw is triggered when processing a specially crafted PDF file. An attacker who has already achieved code execution within a compromised renderer process can leverage this memory corruption bug to escape the Chrome sandbox and execute arbitrary code with the privileges of the browser process. This vulnerability was addressed in Chrome version 148.0.7778.216.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Fixed in Chrome Stable channel update 148.0.7778.216/217
  • 2026-05-28: disclosed: CVE published to NVD

References

Related threats