CVE-2026-9997: Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromi...
Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-9997 is a high-severity Chrome memory safety flaw. If an attacker already compromises Chrome's renderer process, a crafted HTML page could help escape the browser sandbox, increasing the impact from browser compromise to broader system risk.
Executive priority
Treat as urgent browser patching, not emergency incident response based on current evidence. The risk is high because sandbox escape can turn browser compromise into broader endpoint exposure, but no cited source confirms active exploitation.
Technical view
The CVE describes a use-after-free vulnerability in Chrome Input before 148.0.7778.216. The attack path is network-accessible, requires user interaction, and has high complexity. Impact is high for confidentiality, integrity, and availability because scope changes through potential sandbox escape.
Likely exposure
Organizations with Google Chrome installations older than 148.0.7778.216 are the relevant exposure group, especially endpoints browsing untrusted sites. The bundle does not identify affected Chromium-based downstream browsers.
Exploitation context
The provided sources do not show known active exploitation, and KEV status is false. Exploitation requires a compromised renderer process plus a crafted HTML page, so this is a chained or post-renderer-compromise sandbox escape scenario.
Researcher notes
Public detail is limited. The Chromium issue may restrict technical information. Validation should focus on version state and exposure management rather than exploit reproduction. Do not assume downstream Chromium products are affected unless their vendors publish advisories.
Mitigation direction
Update Google Chrome to 148.0.7778.216 or later where available.
Use enterprise browser management to enforce update compliance.
Prioritize users exposed to untrusted web content.
Monitor Google's Chrome release guidance for any revised remediation details.
Validation and detection
Inventory Chrome versions across managed endpoints.
Confirm no managed Chrome installation remains below 148.0.7778.216.
Review browser management telemetry for update failures.
Check vulnerability scanners for CVE-2026-9997 detection updates.
Based on public source material and reviewed before publication.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-416: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references privilege impact, so privilege escalation and authorization behavior review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve
time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
3Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present,
the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-416 · source CWE mapping
Use After Free
Use After Free represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.