Impact
The flaw is an insufficient validation of untrusted input in the ANGLE graphics layer of Google Chrome. If a remote attacker already controls the renderer process, a specially crafted HTML page can trigger a sandbox escape, allowing the attacker to execute code with privileges beyond the browser sandbox. This high‑severity weakness (CWE-20 and CWE-501) undermines system isolation and could compromise the confidentiality and integrity of the operating system.
Affected Systems
Machines running Google Chrome versions earlier than 148.0.7778.216 on any supported platform are affected, as the vulnerability resides in the ANGLE implementation included before that build number.
Risk and Exploitability
The CVSS score of 9.0 indicates a high seriousness. The EPSS score of <1% suggests a very low but non‑zero likelihood of exploitation at present. CVE-2026-9914 is not listed in CISA’s KEV catalog, and exploitation requires that the attacker first gain control of the renderer process, usually by convincing the user to visit a malicious web page or exploit a chain that opens a crafted HTML document.
OpenCVE Enrichment