CVE-2026-9874
A critical vulnerability in Google Chrome's Dawn rendering engine allows a remote attacker to escape the browser sandbox by loading a specially crafted HTML page. The flaw is a use‑after‑free bug that can lead to full system compromise. It affects Chrome versions before 148.0.7778.216 on all major operating systems.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Google Chrome versions prior to 148.0.7778.216 on Windows, macOS, Linux, and other platforms that use the Dawn engine.
Real-world impact
An attacker could run arbitrary code with system privileges, potentially taking control of the victim's computer, stealing data, or installing malware.
Why this severity
The CVSS score of 9.6 reflects the vulnerability's high exploitability (network access, low complexity, no privileges required) and its severe impact (complete compromise of confidentiality, integrity, and availability).
What to do about it
- 01Upgrade Google Chrome to version 148.0.7778.216 or later.
- 02Restart the browser.
NVD-referenced vendor advisory
Timeline
- May 28, 2026 · May 28, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 14d agoAdvisory updatedThe NVD record was last revised.
- Jul 21, 2026 · 14d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- chromereleases.googleblog.com/2026/05/stable-channel-upda…vendor advisory
- issues.chromium.org/issues/500609038permissions required