CVE-2026-9978

8.8

Google · Chrome

A use-after-free vulnerability exists in the Glic component of Google Chrome, potentially allowing remote code execution when processing malicious web content.

Executive summary

A use-after-free vulnerability in Google Chrome's Glic component poses a significant risk of arbitrary code execution for unauthenticated remote attackers via user interaction.

Vulnerability

This is a use-after-free vulnerability (CWE-416) within the Glic feature. An unauthenticated remote attacker could exploit this via a crafted HTML page, requiring user interaction to trigger the condition.

Business impact

The vulnerability carries a CVSS score of 8.8 (High), reflecting the potential for total loss of confidentiality, integrity, and availability. Successful exploitation could allow an attacker to execute arbitrary code within the context of the browser, leading to potential system compromise or unauthorized data access.

Remediation

Immediate Action: Update Google Chrome to version 148.0.7778.216 or later immediately to resolve the vulnerable memory management state.

Proactive Monitoring: Review endpoint security logs for browser crashes or suspicious process spawning patterns associated with the Chrome application.

Compensating Controls: Ensure that browser-based security features, such as site isolation and sandboxing, are fully enabled and not bypassed by local configuration policies.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high severity of this browser-based vulnerability, organizations should prioritize patching all Chrome instances. Standard patch management cycles should be accelerated to ensure that the updated version is deployed across the enterprise environment to mitigate the risk of remote exploitation.

More Google CVEs