Junglewise Threat Intelligence

CVE-2026-9994: Google Chrome use after free in Core component

CVE-2026-9994 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Google Chrome web browser on Windows. An attacker who has already gained control over a website's rendering process could use this flaw to break out of the browser's security sandbox. This could allow the attacker to execute malicious code directly on the underlying operating system, potentially leading to full system compromise and data theft.

Technical details

A use-after-free (UAF) vulnerability exists in the 'Core' component of Google Chrome for Windows. The flaw is reachable via a crafted HTML page. To exploit this, an attacker must first compromise the renderer process (e.g., via a separate vulnerability). Once the renderer is compromised, this UAF allows the attacker to bypass the Chrome sandbox and execute arbitrary code with the privileges of the browser process on the host operating system. The issue is addressed in version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop
  • 2026-05-28: disclosed: NVD publication date

References

Related threats