CVE-2026-9876

Published May 28, 2026

Last updated a month ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-9876 describes a "use after free" vulnerability found within the WebGL component of the Chromium browser. Specifically, this flaw affects Google Chrome on Android versions prior to 148.0.7778.216. This vulnerability could be exploited by a remote attacker. By crafting a malicious HTML page, an attacker might be able to achieve a sandbox escape.

Description
Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Source
chrome-cve-admin@google.com
NVD status
Analyzed
Products
chrome

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.6
Impact score
6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

chrome-cve-admin@google.com
CWE-416

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

12

Configurations