PatchSiren cyber security CVE debrief
CVE-2026-9122 Google CVE debrief
CVE-2026-9122 is a medium-severity information-disclosure issue in Google Chrome on Mac fixed in version 148.0.7778.179. According to the official NVD entry and Google/Chromium references, a remote attacker could use a crafted HTML page to trigger an out-of-bounds read in the GPU component and potentially obtain sensitive data from process memory. The issue is published on 2026-05-20, has CVSS 3.1 score 6.5, and is classified as CWE-125.
- Vendor
- Product
- Chrome
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-20
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-20
- Advisory updated
- 2026-07-23
Who should care
Security teams managing Chrome on macOS, endpoint administrators, SOC analysts monitoring browser risk, and users who regularly browse untrusted web content should prioritize this issue.
Technical summary
Official sources describe an out-of-bounds read in Chrome's GPU path on Mac prior to 148.0.7778.179. The attack requires a crafted HTML page and user interaction, and the expected impact is confidentiality loss through exposure of process memory. NVD maps the weakness to CWE-125 and gives the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N, indicating network reachability, no privileges, and high confidentiality impact.
Defensive priority
Medium. Prioritize prompt patching for managed Mac fleets and any environment where users routinely visit untrusted websites, since the primary risk is memory disclosure rather than code execution or service disruption.
Recommended defensive actions
- Update Google Chrome on Mac to 148.0.7778.179 or later as soon as practical.
- Verify fleet compliance by checking installed Chrome versions on macOS endpoints.
- Treat untrusted HTML content as a trigger vector and consider heightened monitoring until patch deployment is complete.
- Use standard browser hardening and rapid update channels for desktop Chrome deployments.
Evidence notes
The debrief is based on the supplied official sources only: the NVD CVE record, the Chrome release note referenced by Google, and the Chromium issue reference. These sources consistently describe a GPU out-of-bounds read in Google Chrome on Mac, fixed in 148.0.7778.179, with potential memory disclosure via crafted HTML. NVD lists the vulnerability as received and assigns CVSS 6.5 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N) and CWE-125.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-9122 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-9122
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-9122 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9122
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://issues.chromium.org/issues/489579953
[email protected] - Permissions Required
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.