Description
Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-20
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free bug in the XR (extended‑reality) component of Google Chrome on Windows. When a malicious HTML page is loaded, the browser may dereference memory that has already been freed, allowing a remote attacker to execute arbitrary code with the privileges of the user who opens the page. This flaw is a classic Use‑After‑Free weakness (CWE‑416) and is classified as high severity.

Affected Systems

Windows users running any Google Chrome version earlier than 148.0.7778.179 are affected. The issue was tracked in Chromium issue 498702233 and was fixed in the stable‑channel update released on 2026‑05‑08. Build versions on the stable channel older than that may still be vulnerable, while newer stable releases and other channels are not impacted.

Risk and Exploitability

The CVSS score of 8.8 signals a high‑severity flaw, and the EPSS score of <1% indicates that exploitation is currently unlikely, though not impossible. The vulnerability is not listed in the CISA KEV catalog, so no public exploit has been documented as of the time of this analysis. Because the flaw is triggered by a crafted web page, an attacker must obtain a victim’s browsing activity; the potential for widespread impact remains, but the probability of a successful exploit is modest.

Generated by OpenCVE AI on May 29, 2026 at 03:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome for Windows to version 148.0.7778.179 or newer.
  • If an immediate update cannot be deployed, block or disable XR functionality in Chrome through policy or command‑line switches to prevent the vulnerable code path from executing.
  • Continuously monitor Google's release notes and security advisories for additional mitigations or patches.

Generated by OpenCVE AI on May 29, 2026 at 03:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6287-1 chromium security update
History

Fri, 29 May 2026 00:15:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome XR permitting remote code execution chromium-browser: Use after free in XR
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Important


Thu, 21 May 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Wed, 20 May 2026 21:00:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome XR permitting remote code execution

Wed, 20 May 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 20 May 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 20 May 2026 19:30:00 +0000

Type Values Removed Values Added
Description Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-21T03:55:47.527Z

Reserved: 2026-05-20T17:39:23.228Z

Link: CVE-2026-9118

cve-icon Vulnrichment

Updated: 2026-05-20T19:36:37.777Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-20T20:16:43.200

Modified: 2026-05-21T16:45:19.020

Link: CVE-2026-9118

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-19T00:00:00Z

Links: CVE-2026-9118 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T04:00:13Z

Weaknesses