Description
Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted PAC script. (Chromium security severity: Critical)
Published: 2026-05-28
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free bug in the proxy component of Google Chrome enables an attacker to execute arbitrary code by supplying a specially crafted PAC script. This flaw is classified as CWE‑416 and CWE‑825 and is considered critical by Chromium’s own severity assessment.

Affected Systems

All installations of Google Chrome with a version earlier than 148.0.7778.216 that use the proxy functionality are vulnerable. The issue surfaces wherever a PAC script can be processed, which may occur on any platform that runs the affected browser.

Risk and Exploitability

The vulnerability can be triggered remotely by feeding the crafted PAC script through the network. With a CVSS score of 7.8, the flaw poses a high risk, and the EPSS score is < 1%. The issue is not listed in CISA’s KEV catalog, but the nature of the flaw would allow an attacker full code execution on the affected machine. No public exploit has been reported yet, but the EPSS score of < 1% does not mitigate the potential risk.

Generated by OpenCVE AI on May 29, 2026 at 19:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 148.0.7778.216 or newer as released by Google
  • If an upgrade cannot be performed immediately, disable proxy auto‑configuration or PAC script support in browser settings
  • Apply enterprise browser management policies that restrict the use of user‑supplied PAC scripts or block unauthorised proxy connections

Generated by OpenCVE AI on May 29, 2026 at 19:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Fri, 29 May 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Fri, 29 May 2026 12:15:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome Proxy Enables Remote Code Execution via Crafted PAC Script chromium-browser: Use after free in Proxy
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Critical


Fri, 29 May 2026 01:00:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome Proxy Enables Remote Code Execution via Crafted PAC Script

Fri, 29 May 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 28 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted PAC script. (Chromium security severity: Critical)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-29T16:18:40.979Z

Reserved: 2026-05-28T17:24:43.898Z

Link: CVE-2026-9887

cve-icon Vulnrichment

Updated: 2026-05-29T16:17:59.116Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-28T23:16:46.687

Modified: 2026-05-29T18:40:35.380

Link: CVE-2026-9887

cve-icon Redhat

Severity : Critical

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-9887 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T20:00:05Z

Weaknesses