CVE-2026-9891
A critical vulnerability in Google Chrome allows a remote attacker who has compromised the renderer process to potentially escape the browser sandbox by exploiting a use‑after‑free bug in extensions. The flaw exists in versions before 148.0.7778.216. Updating to the patched version removes the risk.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Google Chrome on Windows, macOS, and Linux, specifically versions prior to 148.0.7778.216.
Real-world impact
An attacker could escape the browser sandbox and execute code with higher privileges, potentially compromising the entire system.
Why this severity
The CVSS score of 9 reflects the high impact on confidentiality, integrity, and availability, and the fact that the vulnerability can be exploited remotely once the renderer process is compromised. The potential damage is severe, hence the critical rating.
What to do about it
- 01Update Google Chrome to version 148.0.7778.216 or later.
- 02Restart Chrome to ensure the new version is running.
NVD description
Timeline
- May 28, 2026 · May 28, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 14d agoAdvisory updatedThe NVD record was last revised.
- Jul 21, 2026 · 14d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- chromereleases.googleblog.com/2026/05/stable-channel-upda…release notesvendor advisory
- issues.chromium.org/issues/513508128permissions required