CVE-2026-9937: Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had...
Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-9937 is a high-severity Chrome for Windows flaw fixed in version 148.0.7778.216. A malicious web page could help an attacker escape Chrome’s sandbox, but only after the renderer process was already compromised and the user visited the crafted page.
Executive priority
Treat this as a prompt browser update priority, especially for Windows fleets. It is not documented as exploited in the provided sources, but successful chaining could bypass Chrome’s sandbox and materially increase endpoint compromise risk.
Technical view
The vulnerability is a use-after-free issue in Chrome UI on Windows before 148.0.7778.216. Google describes potential sandbox escape from a crafted HTML page after renderer compromise. CVSS 8.3 reflects network delivery, required user interaction, high complexity, changed scope, and high confidentiality, integrity, and availability impact.
Likely exposure
Exposure is most relevant to organizations with managed or unmanaged Windows endpoints running Google Chrome before 148.0.7778.216. macOS, Linux, and other Chromium-based products are not named in the provided sources.
Exploitation context
The source bundle does not show CISA KEV listing or active exploitation evidence. The attack path is still serious because sandbox escape can turn a browser compromise into broader endpoint impact, but the published description requires prior renderer compromise and user interaction.
Researcher notes
Key constraints are important: Windows only, Chrome before 148.0.7778.216, CWE-416, crafted HTML, renderer already compromised, and possible sandbox escape. The public bundle lacks exploit details, patch diff context, and confirmation of exploitation in the wild.
Mitigation direction
Update Chrome on Windows to 148.0.7778.216 or later.
Confirm enterprise browser auto-update policies are working.
Prioritize endpoints used by high-risk staff and administrators.
Review Google Chrome release guidance for any additional vendor instructions.
Do not rely on sandboxing alone as a compensating control.
Validation and detection
Inventory Windows endpoints for installed Chrome versions.
Flag Chrome versions earlier than 148.0.7778.216.
Verify the Chrome stable update reached managed devices.
Check browser management consoles for update failures or pinned versions.
Track CISA KEV and Google advisories for exploitation updates.
Based on public source material and reviewed before publication.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-416: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references privilege impact, so privilege escalation and authorization behavior review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve
time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
3Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present,
the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-416 · source CWE mapping
Use After Free
Use After Free represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.