Description
Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-05-28
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in the Network component of Google Chrome allows a remote attacker to execute arbitrary code that runs inside the browser’s sandbox. The vulnerability is a classic CWE‑416 use‑after‑free, and also maps to CWE‑825. If exploited, the attacker can run attacker‑supplied code within the sandboxed process, potentially leading to privilege escalation within the user’s system through other browser vulnerabilities or side channels.

Affected Systems

All Google Chrome releases prior to 148.0.7778.216 are affected. The issue was fixed in the 148.0.7778.216 update and all later versions, regardless of operating system. Administrators should verify that their deployed Chrome instances use a version equal to or greater than 148.0.7778.216.

Risk and Exploitability

The CVSS score of 8.8 reflects high severity, and the Chromium team labeled the flaw as Critical. The EPSS score is not available, so exploitation likelihood cannot be quantified, but the lack of a KEV listing suggests no widespread public exploitation as of now. The most probable attack vector is a malicious or compromised web page that, when loaded in the vulnerable browser, delivers a crafted payload that triggers the use‑after‑free and runs code inside the sandbox.

Generated by OpenCVE AI on May 29, 2026 at 14:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 148.0.7778.216 or newer as soon as possible
  • Configure enterprise policy to enforce automatic updates so that all client machines receive the fix without manual intervention
  • If a patch cannot be applied immediately, block access to untrusted web content or enforce strict content isolation to minimize exposure to malicious HTML pages

Generated by OpenCVE AI on May 29, 2026 at 14:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Fri, 29 May 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: Use after free in Network
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Critical


Fri, 29 May 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 29 May 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 28 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-29T11:03:53.465Z

Reserved: 2026-05-28T17:24:40.616Z

Link: CVE-2026-9873

cve-icon Vulnrichment

Updated: 2026-05-29T10:41:41.334Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-28T23:16:45.240

Modified: 2026-05-29T17:05:13.967

Link: CVE-2026-9873

cve-icon Redhat

Severity : Critical

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-9873 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T14:30:37Z

Weaknesses