CVE-2026-9996: Out of bounds read in WebRTC in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to o...
Out of bounds read in WebRTC in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
A malicious web page could make vulnerable Chrome on Mac read past intended WebRTC memory boundaries and expose sensitive process memory. The attacker would need a user to open crafted HTML. The issue is confidentiality-focused: sources do not indicate code execution, data modification, or service outage.
Executive priority
Treat this as a prompt browser patching item for Mac fleets, not a crisis absent exploitation evidence. The business concern is potential exposure of sensitive memory from user browsing activity, so managed update coverage should be verified quickly.
Technical view
CVE-2026-9996 is a CWE-125 out-of-bounds read in Chrome’s WebRTC implementation on Mac before 148.0.7778.216. CVSS 3.1 is 6.5: network reachable, low complexity, no privileges, user interaction required, high confidentiality impact, no integrity or availability impact.
Likely exposure
Organizations with macOS endpoints running Google Chrome below 148.0.7778.216 are the relevant exposure population. Risk is higher where users browse untrusted sites, use unmanaged browsers, or lack timely Chrome update enforcement.
Exploitation context
The provided sources describe remote exploitation through a crafted HTML page, requiring user interaction. The bundle does not show CISA KEV listing or cited evidence of active exploitation. Public issue details may be limited, so exploit maturity is not established from these sources.
Researcher notes
The evidence supports a WebRTC out-of-bounds read with confidentiality impact only. Do not assume Windows, Linux, Edge, or other Chromium-based products are affected from this bundle. The affected/fixed version wording should be reconciled against Google’s stable-channel advisory during remediation tracking.
Mitigation direction
Update Chrome on Mac to 148.0.7778.216 or the vendor-recommended later stable build.
Enforce Chrome auto-update through endpoint or browser management policy.
Prioritize macOS users with high-risk browsing or sensitive browser sessions.
Check Google’s Chrome release guidance for any additional vendor instructions.
Validation and detection
Inventory macOS endpoints for installed Chrome versions below 148.0.7778.216.
Confirm update policy status and successful browser restart after patching.
Review vulnerability scanner results for CVE-2026-9996 coverage.
Check whether managed browser channels align with the stable release guidance.
Based on public source material and reviewed before publication.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-125: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve
time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present,
the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-125 · source CWE mapping
Out-of-bounds Read
Out-of-bounds Read represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.