Description
Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-28
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free in GPU code that can allow a remote attacker who has already compromised the renderer process to escape the sandbox by loading a specially crafted HTML page. Leveraging a freed object access, an attacker may hijack control flow and execute arbitrary code outside the renderer sandbox. Based on the description, this could potentially enable arbitrary code execution beyond the sandbox boundaries, which could lead to broader system compromise.

Affected Systems

Google Chrome is affected, specifically any releases prior to version 148.0.7778.216. The issue applies to desktop builds of the stable channel and may impact all users running those versions where GPU acceleration is enabled.

Risk and Exploitability

Chromium classifies the severity as High with a CVSS score of 8.3, and the EPSS score is below 1%, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a remote attacker delivering a malicious webpage to a user’s browser; the attacker must, however, already have compromised the renderer process to benefit from the use‑after‑free. Given the lack of public exploitation data, the risk remains theoretical but significant enough to warrant immediate attention.

Generated by OpenCVE AI on May 29, 2026 at 16:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome 148.0.7778.216 or newer as soon as possible to obtain the vendor fix.
  • If an upgrade cannot be performed immediately, run Chrome with the "--disable-gpu" flag or disable GPU acceleration in the settings to remove the code path that triggers the use‑after‑free.
  • As a temporary defense, restrict browsing to trusted sites or deploy a strict content‑security‑policy that blocks inline scripts and only allows resources from known origins.

Generated by OpenCVE AI on May 29, 2026 at 16:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Fri, 29 May 2026 12:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome GPU Allows Renderer Sandbox Escape chromium-browser: Use after free in GPU
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}

threat_severity

Important


Fri, 29 May 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 29 May 2026 01:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome GPU Allows Renderer Sandbox Escape

Thu, 28 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-30T03:56:34.213Z

Reserved: 2026-05-28T17:24:45.545Z

Link: CVE-2026-9894

cve-icon Vulnrichment

Updated: 2026-05-29T14:51:53.416Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-28T23:16:47.393

Modified: 2026-05-29T16:16:35.907

Link: CVE-2026-9894

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-9894 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T17:00:04Z

Weaknesses