Junglewise Threat Intelligence

CVE-2026-9880: Google Chrome sandbox escape in WebGL

CVE-2026-9880 · Severity: info · CVSS 9.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A critical security vulnerability in its WebGL component could allow a malicious website to bypass the browser's security sandbox. If exploited, an attacker who has already gained limited control over a browser tab could escalate their access to the underlying operating system, potentially leading to full system compromise and data theft.

Technical details

A critical vulnerability exists in the WebGL component of Google Chrome due to insufficient validation of untrusted input. The flaw allows a remote attacker who has already compromised the renderer process to perform a sandbox escape. By enticing a user to visit a specially crafted HTML page, the attacker can leverage this input validation failure to execute code outside of the restricted browser environment. This vulnerability was addressed in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-04-17: disclosed: Reported by Google internal researchers
  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: advisory: NVD publication date

References

Related threats