Description
Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-28
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This flaw is a use‑after‑free bug in the Document Object Model handling of Google Chrome. A remote attacker who delivers a specially crafted web page can trigger the bug and get the renderer to execute arbitrary code, although the execution occurs within the browser sandbox. The weakness corresponds to CWE‑416, which is a classic instance of memory corruption that permits arbitrary code execution. The flaw also corresponds to CWE‑825, indicating improper release of resources.

Affected Systems

All installations of Google Chrome running versions older than 148.0.7778.216 are potentially vulnerable. The defect exists in the stable channel releases prior to that build and affects all platforms that ship the same renderer code.

Risk and Exploitability

Because the vulnerability can be triggered by any HTML file served over the network, an attacker who can influence HTTP responses to a user can exploit it without further interaction. The CVSS assessment classifies it as High severity with a CVSS score of 8.8, and no exploitation probability estimate is available from EPSS data, while it is not listed in CISA’s KEV catalog. The impact is to allow code execution inside the browser sandbox, which could facilitate privilege escalation or bypass of content‑security restrictions.

Generated by OpenCVE AI on May 29, 2026 at 13:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 148.0.7778.216 or later.
  • If an immediate upgrade is not possible, avoid loading untrusted web content from untrusted sources or disable JavaScript in the affected pages until a patch is applied.
  • Ensure that the browser’s sandboxing features remain enabled and no custom launch flags that disable them are used.

Generated by OpenCVE AI on May 29, 2026 at 13:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Fri, 29 May 2026 12:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in DOM Allows Remote Code Execution via Crafted HTML in Chrome chromium-browser: Use after free in DOM
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Important


Fri, 29 May 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 29 May 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 29 May 2026 00:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in DOM Allows Remote Code Execution via Crafted HTML in Chrome

Thu, 28 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-29T11:02:22.413Z

Reserved: 2026-05-28T17:24:46.199Z

Link: CVE-2026-9897

cve-icon Vulnrichment

Updated: 2026-05-29T10:37:48.403Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-28T23:16:47.703

Modified: 2026-05-29T18:08:13.907

Link: CVE-2026-9897

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-9897 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T13:45:45Z

Weaknesses