Junglewise Threat Intelligence

CVE-2026-9918: Google Chrome sandbox escape in Tint

CVE-2026-9918 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its Tint component could allow a malicious website to break out of the browser's security sandbox. If successful, this could allow an attacker to gain unauthorized access to the underlying operating system or user data.

Technical details

A vulnerability classified as an 'inappropriate implementation' exists in Tint, the compiler for the WebGPU Shading Language (WGSL) used in Google Chrome. The flaw is reachable via a specially crafted HTML page. By exploiting this issue, a remote attacker could bypass the Chrome sandbox, which is designed to isolate the browser process from the rest of the system. This vulnerability was assigned a 'High' severity rating by Chromium. Users are advised to update to version 148.0.7778.216 or later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: disclosed: CVE published to NVD

References

Related threats