CVE-2026-9990: Use after free in WebAppInstalls
Chromium: CVE-2026-9990 Use after free in WebAppInstalls
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 148.0.7778.216 - Upgrade
Upgrade
Google Chrome / Chromiumto a version that resolves this vulnerability.Fixed in 148.0.7778.216 - Compensating control
If you cannot upgrade immediately, reduce exposure to this issue by preventing remote attackers from delivering and having users open crafted HTML pages that rely on specific UI gestures.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-9872
- CVE-2026-9873
- CVE-2026-9874
- CVE-2026-9875
- CVE-2026-9876
- CVE-2026-9877
- CVE-2026-9878
- CVE-2026-9879
- CVE-2026-9880
- CVE-2026-9881
- CVE-2026-9882
- CVE-2026-9883
- CVE-2026-9884
- CVE-2026-9885
- CVE-2026-9886
- CVE-2026-9887
- CVE-2026-9888
- CVE-2026-9889
- CVE-2026-9890
- CVE-2026-9891
- CVE-2026-9892
- CVE-2026-9893
- CVE-2026-9894
- CVE-2026-9895
- CVE-2026-9896
- CVE-2026-9897
- CVE-2026-9898
- CVE-2026-9899
- CVE-2026-9900
- CVE-2026-9901
- CVE-2026-9902
- CVE-2026-9903
- CVE-2026-9904
- CVE-2026-9905
- CVE-2026-9906
- CVE-2026-9907
- CVE-2026-9908
- CVE-2026-9909
- CVE-2026-9910
- CVE-2026-9911
- CVE-2026-9912
- CVE-2026-9913
- CVE-2026-9914
- CVE-2026-9915
- CVE-2026-9916
- CVE-2026-9917
- CVE-2026-9918
- CVE-2026-9919
- CVE-2026-9920
- CVE-2026-9921
- CVE-2026-9922
- CVE-2026-9923
- CVE-2026-9924
- CVE-2026-9925
- CVE-2026-9926
- CVE-2026-9927
- CVE-2026-9928
- CVE-2026-9929
- CVE-2026-9930
- CVE-2026-9931
- CVE-2026-9932
- CVE-2026-9933
- CVE-2026-9934
- CVE-2026-9935
- CVE-2026-9936
- CVE-2026-9937
- CVE-2026-9938
- CVE-2026-9939
- CVE-2026-9940
- CVE-2026-9941
- CVE-2026-9942
- CVE-2026-9943
- CVE-2026-9944
- CVE-2026-9945
- CVE-2026-9946
- CVE-2026-9947
- CVE-2026-9948
- CVE-2026-9949
- CVE-2026-9950
- CVE-2026-9951
- CVE-2026-9952
- CVE-2026-9953
- CVE-2026-9954
- CVE-2026-9955
- CVE-2026-9956
- CVE-2026-9957
- CVE-2026-9958
- CVE-2026-9959
- CVE-2026-9960
- CVE-2026-9961
- CVE-2026-9962
- CVE-2026-9963
- CVE-2026-9964
- CVE-2026-9965
- CVE-2026-9966
- CVE-2026-9967
- CVE-2026-9968
- CVE-2026-9969
- CVE-2026-9970
- CVE-2026-9971
- CVE-2026-9972
- CVE-2026-9973
- CVE-2026-9974
- CVE-2026-9975
- CVE-2026-9976
- CVE-2026-9977
- CVE-2026-9978
- CVE-2026-9979
- CVE-2026-9980
- CVE-2026-9981
- CVE-2026-9982
- CVE-2026-9983
- CVE-2026-9984
- CVE-2026-9985
- CVE-2026-9986
- CVE-2026-9987
- CVE-2026-9988
- CVE-2026-9989
- CVE-2026-9991
- CVE-2026-9992
- CVE-2026-9993
- CVE-2026-9994
- CVE-2026-9995
- CVE-2026-9996
- CVE-2026-9997
- CVE-2026-9998
- CVE-2026-9999
- CVE-2026-10000
- CVE-2026-10001
- CVE-2026-10002
- CVE-2026-10003
- CVE-2026-10004
- CVE-2026-10005
- CVE-2026-10006
- CVE-2026-10007
- CVE-2026-10008
- CVE-2026-10009
- CVE-2026-10010
- CVE-2026-10011
- CVE-2026-10012
- CVE-2026-10013
- CVE-2026-10014
- CVE-2026-10015
- CVE-2026-10016
- CVE-2026-10017
- CVE-2026-10018
- CVE-2026-10019
- CVE-2026-10020
- CVE-2026-10021
- CVE-2026-10022
Frequently Asked Questions
What is the severity of CVE-2026-9990?
The severity of CVE-2026-9990 is rated high with a score of 7.5 according to the CVSS 3.1.
How does CVE-2026-9990 affect users of Microsoft Edge?
CVE-2026-9990 affects users of Microsoft Edge as it ingests Chromium components, which contain this vulnerability.
What is a use after free vulnerability as seen in CVE-2026-9990?
A use after free vulnerability, like CVE-2026-9990, occurs when a program continues to use memory after it has been freed, potentially leading to arbitrary code execution.
How do I fix CVE-2026-9990?
To fix CVE-2026-9990, update to the latest version of Google Chrome or Microsoft Edge that addresses the vulnerability.
What products are affected by CVE-2026-9990?
CVE-2026-9990 affects Google Chrome and Microsoft Edge (Chromium-based) prior to the latest security updates.