Junglewise Threat Intelligence

CVE-2026-9976: Google Chrome remote code execution in USB

CVE-2026-9976 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security flaw in its USB handling component could allow a malicious website to execute unauthorized code on a user's computer. This could lead to the theft of sensitive information, unauthorized access to the system, or the installation of malware if a user visits a specially crafted webpage.

Technical details

A vulnerability exists in the WebUSB implementation within Google Chrome. The flaw is characterized as an 'inappropriate implementation' which allows for remote code execution (RCE). An attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to execute arbitrary code within the context of the browser process. The vulnerability was addressed in Chrome version 148.0.7778.216 and later. Chromium developers rated this as High severity.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop.
  • 2026-05-28: disclosed: CVE published to NVD.

References

Related threats