Sandbox Escape Vulnerability in Google Chrome for Mac
CVE-2026-9972

8.3HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
28 May 2026

What is CVE-2026-9972?

A vulnerability in Google Chrome for Mac allows a remote attacker to exploit uninitialized use in the gamepad component. By crafting a malicious HTML page, an attacker could potentially escape the sandbox, putting users at risk. This issue affects versions of Chrome prior to 148.0.7778.216 and emphasizes the importance of keeping browser software up to date to mitigate potential security threats.

Affected Version(s)

Chrome 148.0.7778.216

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.