Junglewise Threat Intelligence

CVE-2026-9895: Google Chrome out of bounds read in GPU

CVE-2026-9895 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics processing component could allow a malicious website to bypass security protections. If a user visits a specially crafted webpage, an attacker who has already gained limited control over the browser's rendering process could fully escape the security 'sandbox' to access the underlying system. This could lead to unauthorized access to sensitive data or the execution of malicious software on the user's computer.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the GPU component of Google Chrome. The flaw is exploitable by a remote attacker who has already compromised the renderer process, typically through a separate vulnerability. By enticing a user to visit a malicious HTML page, the attacker can leverage this memory corruption issue to achieve a sandbox escape, moving from the restricted renderer process to the more privileged GPU process or the host operating system. This vulnerability was addressed in Chrome version 148.0.7778.216.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for Desktop
  • 2026-05-28: disclosed: NVD publication date

References

Related threats