Google Chrome Stable 148.0.7778.178/179 — CVE-2026-9111 WebRTC Use-After-Free RCE & CVE-2026-9110 UI Inappropriate Implementation (16 CVEs Patched) — Threadlinqs Intelligence
As of 2026-05-30, Google Chrome Stable 148.0.7778.178/179 — CVE-2026-9111 WebRTC Use-After-Free RCE & CVE-2026-9110 UI Inappropriate Implementation (16 CVEs Patched) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-0554 · Severity: CRITICAL · CVSS: 8.8 · Status: PATCHED · Category: VULNERABILITY
Google issued an out-of-band Chrome Stable channel update (148.0.7778.178/179 for Windows/Mac, 148.0.7778.178 for Linux) on 2026-05-21 fixing 16 vulnerabilities, including two Critical-severity flaws.
On 2026-05-21 Google promoted Chrome 148.0.7778.178/179 to the Stable channel for Windows and macOS (and 148.0.7778.178 for Linux), an emergency security release that closes sixteen distinct memory-safety and logic vulnerabilities across the browser's renderer, GPU, networking, ServiceWorker, XR, Chromecast, and UI subsystems. The release is dominated by two Critical-severity issues that Google's own internal fuzzing/audit teams uncovered on 2026-04-20.
CVE-2026-9111 is a Use-After-Free in WebRTC. The WebRTC stack — which handles real-time audio/video peer connections and is implicitly exposed to any cross-origin page through media APIs and ICE candidate gathering — frees an object while a still-live reference is retained on another execution path. An attacker hosting (or injecting) a malicious web page can trigger the stale reference by orchestrating a specific sequence of RTCPeerConnection / data-channel / SDP operations, causing the renderer to dereference freed memory. Combined with a heap-spray primitive, this yields arbitrary read/write in the renderer process and, after chaining a sandbox-escape (historically via GPU, IPC, or kernel bugs), full code execution on the host. The WebRTC attack surface has been a recurring source of Chrome critical-severity bugs (CVE-2023-7024 was actively exploited in the wild in late 2023), and Google's decision to classify CVE-2026-9111 as Critical — the highest tier in Chromium's severity guidelines — indicates the bug is reachable with little or no user interaction beyond visiting a page.
CVE-2026-9110 is an Inappropriate Implementation in the UI layer. Chromium uses this CWE-class for flaws where browser chrome, prompts, or origin/security indicators behave inconsistently with their intended security model — typical impact is omnibox/URL-bar spoofing, permission-prompt bypass, or evasion of Site-Isolation/Cross-Origin Read Blocking enforcement at the UI boundary. While not itself an RCE primitive, a Critical-rated UI bypass undermines the user's ability to recognize a malicious origin and is commonly chained into phishing, downloaded-file masquerading, or extension-permission escalation flows.
The remaining fourteen issues include High-severity Use-After-Free flaws in GPU (CVE-2026-9112, $11,000 bounty to external researcher c6eed09fc8b174b0f3eebedcceb1e792), QUIC (CVE-2026-9114), WebRTC (CVE-2026-9120), and XR (CVE-2026-9118); a GPU out-of-bounds read (CVE-2026-9113, $3,000); ServiceWorker insufficient policy enforcement (CVE-2026-9115, CVE-2026-9116); GFX type confusion (CVE-2026-9117); a WebRTC heap buffer overflow (CVE-2026-9119); plus Medium-severity GPU out-of-bounds reads (CVE-2026-9121, CVE-2026-9122 — credited to David Korczynski / Adalogics and an external researcher), a Chromecast heap buffer overflow (CVE-2026-9123), insufficient input validation (CVE-2026-9124), and a DOM use-after-free (CVE-2026-9126).
No public PoC or in-the-wild exploitation has been reported as of 2026-05-21, but Chrome critical-severity Use-After-Free bugs reliably attract exploit-development attention within days of patch publication via binary diff. Defenders should expect weaponization of CVE-2026-9111 (and possibly CVE-2026-9120/9119 against unpatched populations) within 7–14 days, mirroring the historical exploitation timeline for Chrome WebRTC bugs. Chrome's auto-update is staged over days; managed-enterprise fleets that disable auto-update or pin versions are the highest-risk population. Additionally, all Chromium downstreams — Microsoft Edge, Brave, Opera, Vivaldi, Arc, and embedded Electron/CEF applications — inherit these flaws until they ship their own merged builds.
Weaknesses (CWE)
CWE-416, CWE-1188, CWE-125, CWE-122, CWE-843, CWE-693, CWE-20
Target sectors: all-sectors, government, financial, healthcare, technology, education, manufacturing, media, retail, energy
Target regions: Global, North America, Europe, Asia-Pacific, Latin America, Middle East, Africa
Timeline
- Google security team internally discovers CVE-2026-9111 (WebRTC Use-After-Free) and CVE-2026-9110 (UI Inappropriate Implementation) during routine fuzzing/audit of Chrome Stable.
- Chromium security team triages both criticals, classifies under Chromium Security Severity Guidelines as Critical (renderer RCE / UI security boundary bypass).
- Patches for all 16 CVEs merged into Chromium main branch and cherry-picked to the 148.0.7778.x release branch; internal regression and ASAN testing performed.
- Google promotes Chrome 148.0.7778.178/179 to Stable channel for Windows/macOS and 148.0.7778.178 for Linux; Chrome Releases blog publishes advisory listing 16 fixed CVEs.
- Cyber Security News publishes coverage; CVE entries appear in NVD and MITRE; binary-diff exploit-development window opens for unpatched Chromium downstreams.
- Expected merge window for Microsoft Edge, Brave, Opera, Vivaldi, Electron, and CEF downstreams to incorporate Chromium 148.0.7778.178; pre-merge users remain exposed.
- Projected 7-day weaponization horizon for CVE-2026-9111 based on historical Chrome WebRTC UAF timelines (e.g., CVE-2023-7024 exploited within days of patch).
- As of 2026-05-29, Chrome 148.0.7778.178/179 shipped the fix for all 16 CVEs (incl. critical CVE-2026-9111/9110) and is auto-updating; both criticals were Google-internal finds, never exploited in the wild, EPSS ~0%, and absent from CISA KEV. The projected ~05-28 weaponization horizon passed with no public PoC or attacks, so the threat is patched and not a live concern.
Detections & IOCs
As of 2026-09-04, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-9110, CVE-2026-9111, CVE-2026-9112, CVE-2026-9113, CVE-2026-9114, CVE-2026-9115, CVE-2026-9116, CVE-2026-9117, CVE-2026-9118, CVE-2026-9119, T1189, T1566, T1566.002, T1203, T1204, T1204.001, T1055, T1211, T1684.001, T1217