CVE-2026-9940: Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potenti...
Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
This is a high-severity Chrome memory-safety flaw in ANGLE. A malicious web page could potentially corrupt heap memory after a user visits it. The provided sources do not show active exploitation or KEV listing, but browser flaws with this profile deserve fast enterprise patching.
Executive priority
Treat as a near-term patching priority for all managed desktops. It is not supported as an emergency zero-day from the provided evidence, but the browser attack surface and high CVSS score justify accelerated rollout and verification.
Technical view
CVE-2026-9940 is a CWE-122 heap buffer overflow in ANGLE affecting Google Chrome prior to 148.0.7778.216, with CVSS 8.8. The attack vector is network-based, requires user interaction, and may allow confidentiality, integrity, and availability impact through heap corruption from crafted HTML.
Likely exposure
Organizations with desktop Chrome installations older than 148.0.7778.216 are the likely exposure. Risk is highest for users who browse untrusted sites or receive links from external sources. The source bundle does not identify other affected products.
Exploitation context
The CVE describes potential exploitation via a crafted HTML page. User interaction is required. The source bundle marks KEV as false and provides no cited evidence of active exploitation, public exploit availability, or weaponized campaigns.
Researcher notes
Public detail is limited. The Chromium issue may be restricted, and the bundle does not include root-cause specifics beyond ANGLE heap buffer overflow and crafted HTML. Avoid assuming exploitability details, affected platforms beyond Chrome desktop context, or mitigations beyond vendor update guidance.
Mitigation direction
Update Chrome through the Stable Channel to the vendor-fixed build or later.
Prioritize managed desktop fleets and users exposed to untrusted web content.
Confirm enterprise update controls are not delaying Chrome security updates.
Monitor Google’s advisory and Chromium issue for revised guidance.
Validation and detection
Inventory Chrome versions and flag builds before 148.0.7778.216.
Based on public source material and reviewed before publication.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-122: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve
time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
3Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present,
the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-122 · source CWE mapping
Heap-based Buffer Overflow
Heap-based Buffer Overflow represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.