Google Chrome Stable 148.0.7778.178/179 — CVE-2026-9111 WebRTC Use-After-Free RCE & CVE-2026-9110 UI Inappropriate Implementation (16 CVEs Patched)

Google Chrome Stable 148.0.7778.178/179 (TL-2026-0554), also tracked as Chrome Stable 148.0.7778.178/179 Update, is a critical-severity software vulnerability scored CVSS 8.8, first published 2026-05-21. It has no confirmed attribution, affects Google Chrome, references 16 CVEs (CVE-2026-9110, CVE-2026-9111, CVE-2026-9112), maps to 16 MITRE ATT&CK techniques (T1005, T1055, T1071.001), and is covered by 9 detection rules and 16 indicators of compromise.

Key facts for TL-2026-0554

Threat ID
TL-2026-0554
Also known as
Chrome Stable 148.0.7778.178/179 Update, Chrome May 2026 Critical Update, Chrome WebRTC UAF May 2026
Severity
CRITICAL
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
2026-05-21
Last reviewed
2026-05-21
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
all-sectors, government, financial, healthcare, technology, education, manufacturing, media, retail, energy
Target regions
Global, North America, Europe, Asia-Pacific, Latin America, Middle East, Africa
Detection rules
9
Indicators of compromise
16

Google issued an out-of-band Chrome Stable channel update (148.0.7778.178/179 for Windows/Mac, 148.0.7778.178 for Linux) on 2026-05-21 fixing 16 vulnerabilities, including two Critical-severity flaws. CVE-2026-9111 is a Use-After-Free in WebRTC permitting remote code execution inside the renderer sandbox via a malicious web page, and CVE-2026-9110 is an Inappropriate Implementation in the UI layer enabling security-restriction bypass and browser interface spoofing. Both criticals were discovered internally by Google's security team on 2026-04-20; the remainder span High-severity Use-After-Free flaws in GPU, QUIC, WebRTC, XR, plus ServiceWorker policy bypasses and a GFX type confusion.

How Google Chrome Stable 148.0.7778.178/179 works

On 2026-05-21 Google promoted Chrome 148.0.7778.178/179 to the Stable channel for Windows and macOS (and 148.0.7778.178 for Linux), an emergency security release that closes sixteen distinct memory-safety and logic vulnerabilities across the browser's renderer, GPU, networking, ServiceWorker, XR, Chromecast, and UI subsystems. The release is dominated by two Critical-severity issues that Google's own internal fuzzing/audit teams uncovered on 2026-04-20.

CVE-2026-9111 is a Use-After-Free in WebRTC. The WebRTC stack — which handles real-time audio/video peer connections and is implicitly exposed to any cross-origin page through media APIs and ICE candidate gathering — frees an object while a still-live reference is retained on another execution path. An attacker hosting (or injecting) a malicious web page can trigger the stale reference by orchestrating a specific sequence of RTCPeerConnection / data-channel / SDP operations, causing the renderer to dereference freed memory. Combined with a heap-spray primitive, this yields arbitrary read/write in the renderer process and, after chaining a sandbox-escape (historically via GPU, IPC, or kernel bugs), full code execution on the host. The WebRTC attack surface has been a recurring source of Chrome critical-severity bugs (CVE-2023-7024 was actively exploited in the wild in late 2023), and Google's decision to classify CVE-2026-9111 as Critical — the highest tier in Chromium's severity guidelines — indicates the bug is reachable with little or no user interaction beyond visiting a page.

CVE-2026-9110 is an Inappropriate Implementation in the UI layer. Chromium uses this CWE-class for flaws where browser chrome, prompts, or origin/security indicators behave inconsistently with their intended security model — typical impact is omnibox/URL-bar spoofing, permission-prompt bypass, or evasion of Site-Isolation/Cross-Origin Read Blocking enforcement at the UI boundary. While not itself an RCE primitive, a Critical-rated UI bypass undermines the user's ability to recognize a malicious origin and is commonly chained into phishing, downloaded-file masquerading, or extension-permission escalation flows.

The remaining fourteen issues include High-severity Use-After-Free flaws in GPU (CVE-2026-9112, $11,000 bounty to external researcher c6eed09fc8b174b0f3eebedcceb1e792), QUIC (CVE-2026-9114), WebRTC (CVE-2026-9120), and XR (CVE-2026-9118); a GPU out-of-bounds read (CVE-2026-9113, $3,000); ServiceWorker insufficient policy enforcement (CVE-2026-9115, CVE-2026-9116); GFX type confusion (CVE-2026-9117); a WebRTC heap buffer overflow (CVE-2026-9119); plus Medium-severity GPU out-of-bounds reads (CVE-2026-9121, CVE-2026-9122 — credited to David Korczynski / Adalogics and an external researcher), a Chromecast heap buffer overflow (CVE-2026-9123), insufficient input validation (CVE-2026-9124), and a DOM use-after-free (CVE-2026-9126).

No public PoC or in-the-wild exploitation has been reported as of 2026-05-21, but Chrome critical-severity Use-After-Free bugs reliably attract exploit-development attention within days of patch publication via binary diff. Defenders should expect weaponization of CVE-2026-9111 (and possibly CVE-2026-9120/9119 against unpatched populations) within 7–14 days, mirroring the historical exploitation timeline for Chrome WebRTC bugs. Chrome's auto-update is staged over days; managed-enterprise fleets that disable auto-update or pin versions are the highest-risk population. Additionally, all Chromium downstreams — Microsoft Edge, Brave, Opera, Vivaldi, Arc, and embedded Electron/CEF applications — inherit these flaws until they ship their own merged builds.

MITRE ATT&CK techniques used in TL-2026-0554

Collection

T1005 Data from Local System; T1185 Browser Session Hijacking

Defense Evasion

T1055 Process Injection; T1211 Exploitation for Stealth; T1684.001 Impersonation

Command and Control

T1071.001 Web Protocols; T1105 Ingress Tool Transfer

Initial Access

T1189 Drive-by Compromise; T1566 Phishing; T1566.002 Spearphishing Link

Execution

T1203 Exploitation for Client Execution; T1204 User Execution; T1204.001 Malicious Link

Discovery

T1217 Browser Information Discovery

Resource Development

T1583 Acquire Infrastructure; T1608.004 Drive-by Target

Affected products and versions in Google Chrome Stable 148.0.7778.178/179

  • Google — Chrome
    Vulnerable versions: < 148.0.7778.178 (Linux); < 148.0.7778.178/179 (Windows, macOS)
    Fixed in: 148.0.7778.178 (Linux); 148.0.7778.178/179 (Windows, macOS)
  • Microsoft — Edge (Chromium)
    Vulnerable versions: all builds prior to merged 148.x security release
    Fixed in: Edge Stable merged build incorporating Chromium 148.0.7778.178
  • Brave Software — Brave Browser
    Vulnerable versions: builds prior to Chromium 148.0.7778.178 merge
    Fixed in: pending vendor merged build
  • Opera — Opera Browser
    Vulnerable versions: builds prior to Chromium 148.0.7778.178 merge
    Fixed in: pending vendor merged build
  • OpenJS Foundation — Electron
    Vulnerable versions: Electron builds bundling Chromium < 148.0.7778.178
    Fixed in: Electron security release incorporating Chromium 148.0.7778.178

Remediation for Google Chrome Stable 148.0.7778.178/179

Patches

  • Chrome Stable 148.0.7778.178 (Linux)
  • Chrome Stable 148.0.7778.178 / 148.0.7778.179 (Windows, macOS)
  • Microsoft Edge Stable channel merged build (released within 24–72 hours of Chrome)
  • Brave, Opera, Vivaldi, Arc — vendor-specific merged builds

Immediate actions

  • Update Google Chrome to 148.0.7778.178 (Linux) or 148.0.7778.178/179 (Windows/macOS) on every managed endpoint immediately — do not wait for staged rollout.
  • Verify via chrome://settings/help that Chrome reports version 148.0.7778.178 or later; force-restart Chrome after update so the new binary is loaded.
  • Patch all Chromium-based browsers as their vendors release merged builds: Microsoft Edge, Brave, Opera, Vivaldi, Arc, Yandex, and Samsung Internet.
  • Inventory and update Electron, CEF, and other embedded Chromium runtimes (Slack, Teams, Discord, VS Code, etc.) — these inherit WebRTC, GPU, and ServiceWorker code paths.
  • Block or sandbox high-risk browser usage on legacy endpoints that cannot be updated immediately.

Workarounds

  • Disable WebRTC via enterprise policy (WebRtcLocalIpsAllowedUrls = []) until patch is deployed — mitigates CVE-2026-9111, CVE-2026-9119, CVE-2026-9120 attack surface.
  • Disable hardware-accelerated GPU compositing via --disable-gpu command-line flag — reduces CVE-2026-9112, CVE-2026-9113, CVE-2026-9117, CVE-2026-9121, CVE-2026-9122 exposure but degrades performance.
  • Block known malvertising/exploit-kit infrastructure at the DNS or proxy layer to reduce drive-by exposure.
  • Restrict browsing to allow-listed corporate sites pending patch deployment for high-value endpoints.

Longer-term hardening

  • Enforce Chrome auto-update via group policy / MDM — disable any administrative override that pins major versions.
  • Deploy Chrome Browser Cloud Management (CBCM) or equivalent enterprise visibility tooling to track per-endpoint browser version.
  • Disable WebRTC for endpoints that do not require real-time voice/video (e.g., locked-down kiosks, finance terminals) via WebRtcLocalIpsAllowedUrls / URLBlocklist policy.
  • Implement browser isolation (RBI) for high-risk users (executives, finance, devops) browsing untrusted destinations.
  • Enable Site Isolation strict mode (default in modern Chrome) and ensure SitePerProcess GPO is enforced.
  • Subscribe to the Chrome Releases blog and integrate Chrome version-tracking into vulnerability management SLAs (target: patch within 48 hours of Stable release for any Critical CVE).

CVEs associated with Google Chrome Stable 148.0.7778.178/179

Weaknesses (CWE) in Google Chrome Stable 148.0.7778.178/179

CWE-416, CWE-1188, CWE-125, CWE-122, CWE-843, CWE-693, CWE-20

Timeline of Google Chrome Stable 148.0.7778.178/179

  • Google security team internally discovers CVE-2026-9111 (WebRTC Use-After-Free) and CVE-2026-9110 (UI Inappropriate Implementation) during routine fuzzing/audit of Chrome Stable.
  • Chromium security team triages both criticals, classifies under Chromium Security Severity Guidelines as Critical (renderer RCE / UI security boundary bypass).
  • Patches for all 16 CVEs merged into Chromium main branch and cherry-picked to the 148.0.7778.x release branch; internal regression and ASAN testing performed.
  • Cyber Security News publishes coverage; CVE entries appear in NVD and MITRE; binary-diff exploit-development window opens for unpatched Chromium downstreams.
  • Google promotes Chrome 148.0.7778.178/179 to Stable channel for Windows/macOS and 148.0.7778.178 for Linux; Chrome Releases blog publishes advisory listing 16 fixed CVEs.
  • Expected merge window for Microsoft Edge, Brave, Opera, Vivaldi, Electron, and CEF downstreams to incorporate Chromium 148.0.7778.178; pre-merge users remain exposed.
  • Projected 7-day weaponization horizon for CVE-2026-9111 based on historical Chrome WebRTC UAF timelines (e.g., CVE-2023-7024 exploited within days of patch).
  • As of 2026-05-29, Chrome 148.0.7778.178/179 shipped the fix for all 16 CVEs (incl. critical CVE-2026-9111/9110) and is auto-updating; both criticals were Google-internal finds, never exploited in the wild, EPSS ~0%, and absent from CISA KEV. The projected ~05-28 weaponization horizon passed with no public PoC or attacks, so the threat is patched and not a live concern.

Sources cited for Google Chrome Stable 148.0.7778.178/179

Threats related to Google Chrome Stable 148.0.7778.178/179

Detection coverage for TL-2026-0554

As of 2026-05-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0554 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats