Junglewise Threat Intelligence

CVE-2026-9906: Google Chrome out of bounds write in GPU

CVE-2026-9906 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its graphics processing component could allow a malicious website to bypass the browser's security 'sandbox.' If exploited, an attacker who has already gained limited control over a browser tab could take full control of the underlying computer system, potentially leading to data theft or malware installation.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the GPU component of Google Chrome. The flaw is reachable by a remote attacker who has already compromised the renderer process, typically via a specially crafted HTML page. By exploiting this memory corruption issue, the attacker can bypass the Chromium sandbox to execute arbitrary code with the privileges of the browser process. This vulnerability was addressed in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: disclosed: NVD publication date

References

Related threats