CVE-2026-9881: Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinc...
Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Critical)
This is a critical Chrome for Mac vulnerability tied to Bluetooth memory handling. The described attack depends on a user installing a malicious Chrome extension, after which the attacker could potentially escape Chrome’s sandbox. No active exploitation is stated in the supplied sources.
Executive priority
Prioritize rapid Chrome update compliance on macOS, especially for workstations with sensitive access. The main business risk is browser sandbox escape after malicious extension installation.
Technical view
CVE-2026-9881 is a CWE-416 use-after-free in Chrome Bluetooth on macOS before 148.0.7778.216. The source describes potential sandbox escape through a crafted Chrome Extension. CVSS is 9.0 with changed scope and high confidentiality, integrity, and availability impact.
Likely exposure
Organizations using Google Chrome on macOS versions prior to 148.0.7778.216 are the relevant exposure population. Risk is higher where users can install unapproved extensions or extension controls are weak.
Exploitation context
The provided description requires convincing a user to install a malicious extension. The bundle marks KEV as false and does not cite public exploitation. Treat exploitation evidence as incomplete, not proven active.
Researcher notes
Focus validation on Chrome macOS version state, extension policy posture, and evidence of suspicious extension installation. The public issue may have limited detail, and the bundle does not provide exploit artifacts or indicators.
Mitigation direction
Update Chrome on macOS to 148.0.7778.216 or later.
Restrict Chrome extension installation to approved enterprise allowlists.
Remove unknown or unnecessary extensions from managed Mac fleets.
Review Chrome release guidance for any additional vendor instructions.
Validation and detection
Inventory Chrome versions on all macOS endpoints.
Confirm managed Macs are at 148.0.7778.216 or later.
Audit installed Chrome extensions for unapproved or suspicious entries.
Based on public source material and reviewed before publication.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-416: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references privilege impact, so privilege escalation and authorization behavior review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve
time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
3Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present,
the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-416 · source CWE mapping
Use After Free
Use After Free represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.