Description
Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-28
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write was discovered in the V8 JavaScript engine used by Google Chrome. The flaw allows a remote attacker to execute arbitrary code inside the browser’s sandbox by serving a specially crafted HTML page, and was rated as a high‑severity issue by Chromium security. The vulnerability focuses on improper bounds checking of memory during script execution, leading to uncontrolled write operations.

Affected Systems

The affected product is Google Chrome before version 148.0.7778.216. All users running any older stable channel build faced potential exploitation when visiting malicious web pages containing the crafted payload.

Risk and Exploitability

The CVSS score of 8.8 reflects a high‑severity flaw, yet the vulnerability is still not listed in CISA KEV and EPSS data is unavailable. Exploitation requires a user to open or trigger the crafted HTML content in a Chrome browser, making the attack vector client‑side. Successful exploitation would compromise the browser sandbox and could lead to arbitrary code execution on the host system. Given the lack of active public exploits, the realistic threat remains moderate to high until an exploit is found or the pending automatic update is deployed.

Generated by OpenCVE AI on May 29, 2026 at 12:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 148.0.7778.216 or later on all affected systems.
  • Configure Chrome to automatically receive security updates to ensure the patch is applied promptly.
  • Enable enhanced sandboxing features such as Site Isolation and GPU sandboxing to add additional layers of protection where available.

Generated by OpenCVE AI on May 29, 2026 at 12:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Fri, 29 May 2026 12:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in V8 Enables Remote Code Execution via Crafted HTML chromium-browser: Out of bounds write in V8
References
Metrics threat_severity

None

threat_severity

Important


Fri, 29 May 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 29 May 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 29 May 2026 01:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in V8 Enables Remote Code Execution via Crafted HTML

Thu, 28 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-787
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-29T11:02:36.839Z

Reserved: 2026-05-28T17:24:45.998Z

Link: CVE-2026-9896

cve-icon Vulnrichment

Updated: 2026-05-29T10:43:54.642Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-28T23:16:47.600

Modified: 2026-05-29T18:08:41.940

Link: CVE-2026-9896

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-9896 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T12:45:16Z

Weaknesses