Junglewise Threat Intelligence

CVE-2026-9117: Google Chrome type confusion in GFX

CVE-2026-9117 · Severity: high · CVSS 7.5 · Published 2026-05-20

Technologies: Google ChromeOS, Google Chrome. Vendors: Google.

Executive brief

Google Chrome and ChromeOS are affected by a security vulnerability in the graphics component. An attacker who has already partially compromised the browser's internal processes could use a specially crafted video file to break out of the security sandbox. This could allow the attacker to gain broader access to the underlying operating system and user data.

Technical details

A type confusion vulnerability exists in the GFX component of Google Chrome on Linux and ChromeOS. The flaw is triggered when processing a specially crafted video file. An attacker who has already achieved code execution within a compromised renderer process can exploit this vulnerability to perform a sandbox escape. This allows the attacker to execute code with the privileges of the browser process rather than the restricted renderer. The issue is addressed in version 148.0.7778.179 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.179
  • Google ChromeOS Prior to 148.0.7778.179

Timeline

  • 2026-04-01: other: Reported by Google internal researchers
  • 2026-05-19: patched: Stable channel update released
  • 2026-05-20: advisory: NVD publication date

References

Related threats