Junglewise Threat Intelligence

CVE-2026-9113: Google Chrome out of bounds read in GPU on macOS

CVE-2026-9113 · Severity: medium · CVSS 4.3 · Published 2026-05-20

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics processing component on macOS could allow a malicious website to read sensitive information from the browser's memory. This occurs when a user visits a specially crafted webpage, potentially leading to the exposure of private data. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the GPU component of Google Chrome for macOS. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to perform unauthorized memory reads. This is a client-side vulnerability requiring user interaction (visiting a malicious site). While the CVSS score is 4.3 (Medium), Chromium developers have assigned it a 'High' severity rating. The issue is resolved in version 148.0.7778.179 for Mac.

Affected products

  • Google Chrome Prior to 148.0.7778.179

Timeline

  • 2026-03-04: other: Reported by researcher
  • 2026-05-19: patched: Stable channel update released
  • 2026-05-20: advisory: NVD publication date

References

Related threats