Junglewise Threat Intelligence

CVE-2026-9930: Google Chrome out of bounds write in Dawn

CVE-2026-9930 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in the Google Chrome web browser for macOS. This flaw allows a malicious website to corrupt the browser's memory when a user visits a specially crafted page. If successfully exploited, this could lead to a browser crash or potentially allow an attacker to execute unauthorized code on the user's computer.

Technical details

An out-of-bounds (OOB) write vulnerability exists in Dawn, the WebGPU implementation in Google Chrome, specifically affecting the macOS version. The flaw is triggered when the browser processes a maliciously crafted HTML page, allowing a remote attacker to perform memory corruption. This is classified as CWE-787 (Out-of-bounds Write). Successful exploitation could lead to arbitrary code execution within the context of the browser renderer process or a denial-of-service (crash). The issue is resolved in Chrome version 148.0.7778.216 for Mac.

Affected products

  • Google Chrome Prior to 148.0.7778.216 on Mac

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop
  • 2026-05-28: disclosed: NVD publication date

References

Related threats