Description
Use after free in TabStrip in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-28
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free within the TabStrip component of Google Chrome, allowing a maliciously crafted web page to trigger UI gestures that corrupt the browser’s heap memory. Depending on the data overwritten, an attacker could tamper with or read sensitive information and potentially execute arbitrary code. This flaw is related to CWE‑416 and CWE‑825, identifying weaknesses in memory management and potential resource handling, respectively.

Affected Systems

Google Chrome desktop versions earlier than 148.0.7778.216 contain the vulnerable TabStrip code. The official fix was included in the stable channel update that began with version 148.0.7778.216; any subsequent Chrome release incorporates the patch.

Risk and Exploitability

The flaw requires a user’s interaction with a specialized URL that prompts specific UI gestures – a scenario most likely arising from a phishing or social‑engineering attack. The CVSS score of 8.8 highlights a high severity, and although the EPSS score is 0.00035 and the issue is not catalogued in the CISA KEV list, the awareness of this use‑after‑free combined with the need for a targeted user action makes this vulnerability a high impact risk for organizations relying on up‑to‑date browser security.

Generated by OpenCVE AI on May 29, 2026 at 15:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 148.0.7778.216 or newer to eliminate the vulnerable TabStrip code path.
  • Enable Chrome’s automatic update mechanism so that the Browser quickly receives all security patches.
  • Reduce the attack surface by discouraging users from interacting with unfamiliar websites, especially those that request unusual UI gestures or interactions.

Generated by OpenCVE AI on May 29, 2026 at 15:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Fri, 29 May 2026 12:15:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip Use-After-Free Leading to Potential Heap Corruption chromium-browser: Use after free in TabStrip
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Fri, 29 May 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 29 May 2026 01:00:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip Use-After-Free Leading to Potential Heap Corruption

Thu, 28 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Use after free in TabStrip in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-29T17:53:28.854Z

Reserved: 2026-05-28T17:24:59.285Z

Link: CVE-2026-9954

cve-icon Vulnrichment

Updated: 2026-05-29T17:53:25.822Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-28T23:16:53.590

Modified: 2026-05-29T19:16:30.297

Link: CVE-2026-9954

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-9954 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T15:45:16Z

Weaknesses