WebGL Remote Code Execution Vulnerability in Google Chrome
CVE-2026-9880

8.3HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
28 May 2026

What is CVE-2026-9880?

A significant vulnerability has been identified in Google Chrome's WebGL implementation. This flaw arises from insufficient validation of untrusted input, which could allow a remote attacker who compromises the renderer process to execute arbitrary code. By crafting a malicious HTML page, the attacker may exploit this vulnerability to escape the sandbox, potentially leading to unauthorized access and control over the affected system. Users are advised to update to the latest version of Google Chrome to mitigate this risk.

Affected Version(s)

Chrome 148.0.7778.216

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.