CVE-2026-9918
A flaw in Google Chrome’s Tint component lets a remote attacker escape the browser sandbox by loading a specially crafted HTML page. The vulnerability can be triggered without any user interaction and may allow the attacker to read or modify files on the host system.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of Google Chrome versions earlier than 148.0.7778.216 are affected. Updating to this version or newer removes the flaw.
Real-world impact
An attacker could gain full control over the victim’s computer, reading sensitive data, installing malware, or modifying system files, all without needing to log in or provide credentials.
Why this severity
The CVSS score of 9.6 reflects that the exploit is remote, requires no authentication, and can compromise confidentiality, integrity, and availability of the system. The high impact and ease of execution make it a critical risk.
What to do about it
- 01Upgrade Google Chrome to version 148.0.7778.216 or later.
- 02Restart the browser to apply the update.
NVD description
Timeline
- May 28, 2026 · May 28, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 15d agoAdvisory updatedThe NVD record was last revised.
- Jul 20, 2026 · 15d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- chromereleases.googleblog.com/2026/05/stable-channel-upda…release notes
- issues.chromium.org/issues/500099471permissions required