Junglewise Threat Intelligence

CVE-2026-9995: Google Chrome use after free in WebXR

CVE-2026-9995 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its WebXR component, which handles virtual and augmented reality content, could allow a malicious website to execute unauthorized code on a user's computer. While this code execution is restricted by the browser's security sandbox, it represents a significant risk to user data and system integrity if combined with other flaws.

Technical details

A use-after-free (UAF) vulnerability exists in the WebXR implementation of Google Chrome. The flaw is triggered when the browser incorrectly manages memory lifecycle for objects used in Extended Reality (XR) sessions. A remote attacker can exploit this by enticing a user to visit a malicious website containing crafted HTML and JavaScript. Successful exploitation allows the attacker to achieve arbitrary code execution (ACE) within the context of the Chrome renderer process sandbox. The vulnerability is addressed in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop versions.
  • 2026-05-28: disclosed: CVE published to the NVD.

References

Related threats