PatchSiren cyber security CVE debrief
CVE-2026-9117 Google CVE debrief
CVE-2026-9117 is a High-severity Chrome issue involving type confusion in GFX on Linux and ChromeOS. The CVE description says a remote attacker who had already compromised the renderer process could potentially achieve a sandbox escape by using a crafted video file. Affected builds are Chrome prior to 148.0.7778.179.
- Vendor
- Product
- Chrome
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-20
- Original CVE updated
- 2026-05-21
- Advisory published
- 2026-05-20
- Advisory updated
- 2026-05-21
Who should care
Browser and endpoint security teams, Chrome/ChromeOS administrators, and defenders responsible for Linux and ChromeOS fleets that rely on Chrome’s sandboxing to contain renderer compromise.
Technical summary
The vulnerability is described as a type confusion flaw in Chrome’s GFX component on Linux and ChromeOS. The stated impact is a potential sandbox escape when a compromised renderer processes a crafted video file. The NVD record lists the CVSS vector AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H and a primary weakness classification of CWE-843.
Defensive priority
High. Prioritize remediation on Chrome and ChromeOS systems on Linux/ChromeOS, because the issue is described as a potential sandbox escape path after renderer compromise and is rated High by Chromium.
Recommended defensive actions
- Update Google Chrome to 148.0.7778.179 or later on affected Linux and ChromeOS systems.
- Verify ChromeOS devices receive and apply the corresponding stable-channel update.
- Prioritize managed endpoints that regularly open untrusted video content in Chrome.
- Track the linked Google Chrome release note and Chromium issue for any follow-up guidance or clarification.
- Reassess browser isolation assumptions on systems where renderer compromise would be especially high impact.
Evidence notes
This debrief is based on the supplied CVE description and the NVD record for CVE-2026-9117. The NVD entry cites a Google Chrome stable-channel release note and a Chromium issue tracker item as references. No additional facts beyond the supplied corpus were assumed.
Official resources
-
CVE-2026-9117 CVE record
CVE.org
-
CVE-2026-9117 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
-
Source reference
[email protected] - Permissions Required
Publicly disclosed in the NVD record on 2026-05-20, with vendor references pointing to a Google Chrome stable-channel update and a Chromium issue tracker entry.