CVE-2026-9973: Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arb...
Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
This is a high-severity Chrome browser flaw in V8, Chrome's JavaScript engine. A malicious web page could cause memory corruption and let an attacker run code inside Chrome's sandbox. User interaction is required, so exposure is mainly users who can browse attacker-controlled or compromised pages before updating.
Executive priority
Treat this as an urgent browser update issue, not a crisis unless exploitation is later confirmed. Browser RCE bugs are valuable to attackers, and the fix path is straightforward: rapidly verify Chrome update coverage across the fleet.
Technical view
CVE-2026-9973 is a CWE-787 out-of-bounds write in V8 affecting Google Chrome prior to 148.0.7778.216. CVSS 3.1 is 8.8 with network attack vector, low complexity, no privileges, required user interaction, unchanged scope, and high confidentiality, integrity, and availability impact.
Likely exposure
Organizations with desktop Chrome versions before 148.0.7778.216 are the primary exposure. Risk is higher on unmanaged endpoints, delayed update rings, kiosk systems, and users with broad web access. The bundle does not prove exposure for other Chromium-based products.
Exploitation context
The sources describe remote code execution inside a sandbox via a crafted HTML page. The bundle does not show CISA KEV listing or another cited source confirming active exploitation. Public technical details appear limited, with the Chromium issue referenced but not summarized in the bundle.
Researcher notes
The core issue is V8 memory corruption with an out-of-bounds write primitive, but source detail is sparse. Avoid assuming sandbox escape, exploit availability, or downstream product impact without additional vendor evidence. Validate using version state and official release references.
Mitigation direction
Update Google Chrome desktop to 148.0.7778.216 or later.
Confirm browser auto-update is enabled and functioning.
Prioritize unmanaged endpoints and delayed update channels.
Check Google's Chrome release guidance for any platform-specific details.
Monitor CISA KEV and vendor advisories for exploitation updates.
Validation and detection
Inventory Chrome desktop versions across managed and unmanaged endpoints.
Verify deployed Chrome versions are 148.0.7778.216 or later.
Based on public source material and reviewed before publication.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-787: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve
time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
3Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present,
the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-787 · source CWE mapping
Out-of-bounds Write
Out-of-bounds Write represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.