PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9990 Google CVE debrief

A use-after-free vulnerability in Google Chrome's WebAppInstalls component on macOS, rated High severity by Chromium. The flaw exists in versions prior to 148.0.7778.216 and requires user interaction through specific UI gestures to trigger. Successful exploitation could lead to heap corruption, potentially enabling remote code execution. The vulnerability was disclosed via Chrome's stable channel release notes and is tracked in the Chromium issue tracker. No known exploitation in ransomware campaigns has been reported.

Vendor
Google
Product
Chrome
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-28
Original CVE updated
2026-07-21
Advisory published
2026-05-28
Advisory updated
2026-07-21

Who should care

macOS users and administrators running Google Chrome; organizations with bring-your-own-device policies; security teams monitoring browser-based attack vectors

Technical summary

The vulnerability is a use-after-free (CWE-416) in the WebAppInstalls component of Google Chrome on macOS. It requires a remote attacker to convince a user to perform specific UI gestures, after which a crafted HTML page can trigger heap corruption. The CVSS 3.1 vector (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H) reflects network attack vector, high attack complexity, no privileges required, user interaction required, and high impacts to confidentiality, integrity, and availability. The fix is available in Chrome stable channel version 148.0.7778.216.

Defensive priority

high

Recommended defensive actions

  • Update Google Chrome on macOS to version 148.0.7778.216 or later
  • Restrict execution of untrusted HTML content and limit user interaction with untrusted web applications
  • Monitor for anomalous browser crashes or unexpected heap corruption indicators on macOS endpoints
  • Review browser extension and web app installation policies to reduce attack surface
  • Apply principle of least privilege for user accounts to limit impact of potential browser compromise

Evidence notes

CVE published 2026-05-28; modified 2026-05-29. Vendor attribution derived from reference domain 'Googleblog' with low confidence and flagged for review. Chrome release notes and Chromium issue tracker confirm Google as the vendor.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-9990 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-9990

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-9990 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9990

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.