PatchSiren cyber security CVE debrief
CVE-2026-9976 Google CVE debrief
A high-severity inappropriate implementation vulnerability in Google Chrome's USB subsystem allows remote code execution via crafted HTML pages. Affected versions are prior to 148.0.7778.216 on Windows, macOS, and Linux. The vulnerability was published by NVD on 2026-05-28 and modified on 2026-05-29. No known exploitation in ransomware campaigns has been reported.
- Vendor
- Product
- Chrome
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-28
- Original CVE updated
- 2026-07-21
- Advisory published
- 2026-05-28
- Advisory updated
- 2026-07-21
Who should care
Organizations and individuals using Google Chrome versions prior to 148.0.7778.216 on Windows, macOS, or Linux should prioritize updating. Security teams managing browser deployments and those relying on WebUSB functionality should pay particular attention.
Technical summary
The vulnerability stems from an inappropriate implementation in the USB subsystem of Google Chrome. A remote attacker can exploit this flaw by convincing a user to visit a crafted HTML page, leading to arbitrary code execution. The attack requires no privileges and has low attack complexity, though user interaction is required. The confidentiality, integrity, and availability impacts are all rated High.
Defensive priority
high
Recommended defensive actions
- Upgrade Google Chrome to version 148.0.7778.216 or later on all supported platforms (Windows, macOS, Linux).
- Verify automatic update mechanisms are enabled and functioning for Chrome installations.
- Restrict or monitor use of WebUSB APIs where not required for business operations, as the vulnerability resides in the USB implementation.
- Apply security updates promptly given the High CVSS score and remote attack vector via crafted HTML pages.
Evidence notes
CVSS 3.1 score of 8.8 (High) with vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. CWE-94 (Improper Control of Generation of Code) is listed as a secondary weakness. CPE configurations confirm Chrome versions below 148.0.7778.216 are vulnerable across Windows, macOS, and Linux platforms.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-9976 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-9976
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-9976 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9976
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0877304591.html
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://issues.chromium.org/issues/511732828
[email protected] - Permissions Required
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.