Google Chrome Stable 148.0.7778.178/179 — CVE-2026-9111 WebRTC Use-After-Free RCE & CVE-2026-9110 UI Inappropriate Implementation (16 CVEs Patched) — Threadlinqs Intelligence
As of 2026-05-30, Google Chrome Stable 148.0.7778.178/179 — CVE-2026-9111 WebRTC Use-After-Free RCE & CVE-2026-9110 UI Inappropriate Implementation (16 CVEs Patched) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-0554 · Severity: CRITICAL · CVSS: 8.8 · Status: PATCHED · Category: VULNERABILITY
Google issued an out-of-band Chrome Stable channel update (148.0.7778.178/179 for Windows/Mac, 148.0.7778.178 for Linux) on 2026-05-21 fixing 16 vulnerabilities, including two Critical-severity flaws.
On 2026-05-21 Google promoted Chrome 148.0.7778.178/179 to the Stable channel for Windows and macOS (and 148.0.7778.178 for Linux), an emergency security release that closes sixteen distinct memory-safety and logic vulnerabilities across the browser's renderer, GPU, networking, ServiceWorker, XR, Chromecast, and UI subsystems. The release is dominated by two Critical-severity issues that Google's own internal fuzzing/audit teams uncovered on 2026-04-20.
CVE-2026-9111 is a Use-After-Free in WebRTC. The WebRTC stack — which handles real-time audio/video peer connections and is implicitly exposed to any cross-origin page through media APIs and ICE candidate gathering — frees an object while a still-live reference is retained on another execution path. An attacker hosting (or injecting) a malicious web page can trigger the stale reference by orchestrating a specific sequence of RTCPeerConnection / data-channel / SDP operations, causing the renderer to dereference freed memory. Combined with a heap-spray primitive, this yields arbitrary read/write in the renderer process and, after chaining a sandbox-escape (historically via GPU, IPC, or kernel bugs), full code execution on the host. The WebRTC attack surface has been a recurring source of Chrome critical-severity bugs (CVE-2023-7024 was actively exploited in the wild in late 2023), and Google's decision to classify CVE-2026-9111 as Critical — the highest tier in Chromium's severity guidelines — indicates the bug is reachable with little or no user interaction beyond visiting a page.
CVE-2026-9110 is an Inappropriate Implementation in the UI layer. Chromium uses this CWE-class for flaws where browser chrome, prompts, or origin/security indicators behave inconsistently with their intended security model — typical impact is omnibox/URL-bar spoofing, permission-prompt bypass, or evasion of Site-Isolation/Cross-Origin Read Blocking enforcement at the UI boundary. While not itself an RCE primitive, a Critical-rated UI bypass undermines the user's ability to recognize a malicious origin and is commonly chained into phishing, downloaded-file masquerading, or extension-permission escalation flows.
The remaining fourteen issues include High-severity Use-After-Free flaws in GPU (CVE-2026-9112, $11,000 bounty to external researcher c6eed09fc8b174b0f3eebedcceb1e792), QUIC (CVE-2026-9114), WebRTC (CVE-2026-9120), and XR (CVE-2026-9118); a GPU out-of-bounds read (CVE-2026-9113, $3,000); ServiceWorker insufficient policy enforcement (CVE-2026-9115, CVE-2026-9116); GFX type confusion (CVE-2026-9117); a WebRTC heap buffer overflow (CVE-2026-9119); plus Medium-severity GPU out-of-bounds reads (CVE-2026-9121, CVE-2026-9122 — credited to David Korczynski / Adalogics and an external researcher), a Chromecast heap buffer overflow (CVE-2026-9123), insufficient input validation (CVE-2026-9124), and a DOM use-after-free (CVE-2026-9126).
No public PoC or in-the-wild exploitation has been reported as of 2026-05-21, but Chrome critical-severity Use-After-Free bugs reliably attract exploit-development attention within days of patch publication via binary diff. Defenders should expect weaponization of CVE-2026-9111 (and possibly CVE-2026-9120/9119 against unpatched populations) within 7–14 days, mirroring the historical exploitation timeline for Chrome WebRTC bugs. Chrome's auto-update is staged over days; managed-enterprise fleets that disable auto-update or pin versions are the highest-risk population. Additionally, all Chromium downstreams — Microsoft Edge, Brave, Opera, Vivaldi, Arc, and embedded Electron/CEF applications — inherit these flaws until they ship their own merged builds.
Weaknesses (CWE)
CWE-416, CWE-1188, CWE-125, CWE-122, CWE-843, CWE-693, CWE-20
Target sectors: all-sectors, government, financial, healthcare, technology, education, manufacturing, media, retail, energy
Target regions: Global, North America, Europe, Asia-Pacific, Latin America, Middle East, Africa
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-9110, CVE-2026-9111, CVE-2026-9112, CVE-2026-9113, CVE-2026-9114, CVE-2026-9115, CVE-2026-9116, CVE-2026-9117, CVE-2026-9118, CVE-2026-9119, T1189, T1566, T1566.002, T1203, T1204, T1204.001, T1055, T1211, T1656, T1217