Junglewise Threat Intelligence

CVE-2026-9896: Google Chrome out of bounds write in V8

CVE-2026-9896 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its V8 JavaScript engine could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited to the browser's security sandbox, it represents a significant risk to system integrity and user data.

Technical details

An out-of-bounds (OOB) write vulnerability (CWE-787) exists in the V8 JavaScript engine within Google Chrome. The flaw is triggered when the engine processes a specially crafted HTML page, allowing a remote, unauthenticated attacker to perform memory corruption. Successful exploitation enables arbitrary code execution within the Chromium renderer sandbox. The issue was addressed in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop
  • 2026-05-28: disclosed: NVD publication date

References

Related threats