Description
Use after free in Accessibility in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-28
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw in Google Chrome's Accessibility code. An attacker who has already gained access to a compromised renderer process can craft a malicious HTML page that triggers the use‑after‑free. This flaw allows the attacker to escape the renderer sandbox, potentially executing arbitrary code with the privileges of the host operating system. Chromium has labeled the issue as High severity.

Affected Systems

Google Chrome for desktop, any stable channel build prior to version 148.0.7778.216, regardless of operating system.

Risk and Exploitability

The flaw is fatal when combined with a compromised renderer process; it can lead to complete Take‑Over of the host system. The CVSS score of 9.0 and the EPSS score of < 1% indicate a very high severity but a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The inherent severity and the potential for sandbox escape result in a high overall risk. The most probable attack path involves an attacker delivering a specially crafted HTML page to the targeted machine, which exploits the use‑after‑free and then escalates privileges from the renderer to the host.

Generated by OpenCVE AI on May 29, 2026 at 15:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 148.0.7778.216 or later. This release patches the use‑after‑free in Accessibility and removes the sandbox escape path.
  • If updating is not immediately possible, disable the Accessibility feature via Chrome policy or configuration until the patch can be applied; the bug is localized to that component.
  • Keep an eye on future Chrome releases and security advisories; install any subsequent patches as soon as they become available.

Generated by OpenCVE AI on May 29, 2026 at 15:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 29 May 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Fri, 29 May 2026 12:15:00 +0000

Type Values Removed Values Added
Title Use‑after‑Free in Chrome Accessibility Enables Sandbox Escape chromium-browser: Use after free in Accessibility
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}

threat_severity

Important


Fri, 29 May 2026 00:00:00 +0000

Type Values Removed Values Added
Title Use‑after‑Free in Chrome Accessibility Enables Sandbox Escape
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 28 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Use after free in Accessibility in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-29T14:48:23.987Z

Reserved: 2026-05-28T17:24:47.588Z

Link: CVE-2026-9902

cve-icon Vulnrichment

Updated: 2026-05-29T14:48:19.012Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-28T23:16:48.207

Modified: 2026-05-29T16:16:36.683

Link: CVE-2026-9902

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-9902 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T15:45:16Z

Weaknesses