Description
Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)
Published: 2026-05-28
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic use‑after‑free bug (CWE‑416) combined with an uninitialized memory use (CWE‑825) in the Bluetooth handling code of Google Chrome on macOS. An attacker, who can persuade a user to install a malicious Chrome extension, can trigger the‑after‑free through the Bluetooth subsystem and use the uninitialized memory to execute arbitrary code at the user’s privilege level. This flaw directly enables remote code execution, allowing an attacker to compromise the confidentiality, integrity, or availability of the user’s data and system.

Affected Systems

Google Chrome running on macOS versions prior to 148.0.7778.216 are affected. The CNA confirmation places the bug within the Chrome release 148 line; all earlier builds are vulnerable. No other operating systems or browsers are listed as impacted in the current data. The fix is already incorporated into Chrome 148.0.7778.216 and later releases.

Risk and Exploitability

The EPSS score of 0.009% indicates a very low, but non‑zero chance of exploitation. The vulnerability is not currently in the CISA KEV catalog, indicating it has not yet been exploited in the wild or at least has not been formally reported as such. Exploitation would still require social engineering to convince a user to install a malicious extension, followed by an action that triggers the vulnerability through the Bluetooth subsystem. Should an attacker succeed, arbitrary code would run with the privileges of the Chrome process, enabling malware installation, data theft, or further lateral movement. Until a patch is applied, the risk remains that a targeted user may be compromised.

Generated by OpenCVE AI on May 29, 2026 at 18:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Chrome version 148.0.7778.216 or later on macOS to address the use‑after‑free flaw.
  • Disable or remove any extensions that are not from the official Chrome Web Store, and block installation of extensions from unknown sources to mitigate social‑engineering attempts.
  • Monitor the machine for unexpected Chrome crashes or anomalous process activity and consider applying endpoint protection that blocks execution of unsigned binaries generated by Chrome.

Generated by OpenCVE AI on May 29, 2026 at 18:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Fri, 29 May 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 29 May 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: Use after free in Bluetooth
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}

threat_severity

Important


Fri, 29 May 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 28 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-30T03:57:22.098Z

Reserved: 2026-05-28T17:25:02.715Z

Link: CVE-2026-9964

cve-icon Vulnrichment

Updated: 2026-05-29T16:10:29.531Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-28T23:16:54.623

Modified: 2026-05-29T20:33:33.310

Link: CVE-2026-9964

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-9964 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T18:45:05Z

Weaknesses