Junglewise Threat Intelligence

CVE-2026-9939: Google Chrome heap buffer overflow in WebCodecs

CVE-2026-9939 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's WebCodecs component could allow a remote attacker to execute malicious code on a user's computer. This occurs when a user visits a specially crafted website designed to trigger a memory error. While the attack is limited by the browser's security sandbox, it represents a significant risk to data privacy and system integrity if combined with other flaws.

Technical details

A heap-based buffer overflow (CWE-122) exists in the WebCodecs implementation of Google Chrome. The vulnerability is triggered when the browser processes a maliciously crafted HTML page, allowing a remote attacker to overflow memory in the heap area. This can lead to arbitrary code execution within the context of the browser's sandboxed process. The issue is fixed in Chrome version 148.0.7778.216 and later. Attackers require no special privileges other than convincing a user to navigate to a malicious URL.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop
  • 2026-05-28: disclosed: NVD publication date

References

Related threats