CVE-2026-9110Patch(apple / chrome)

HIGHCVSS 4.2 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Critical)

6.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-451

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-22); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-21: 1Mentions · 2026-05-22: 2Mentions · 2026-05-23: 1PoC Mentioned / Linked · 2026-05-23: 1Active Exploitation · 2026-05-23: 1Patch / Workaround · 2026-05-22: 1Patch / Workaround · 2026-05-23: 1Technical Details · 2026-05-21: 1Technical Details · 2026-05-22: 2Technical Details · 2026-05-23: 105-2105-2205-23
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-211
Disclosure1
2026-05-222
General1Patch1
2026-05-231
Patch1
Full discourse4 posts
  • Cyber News Live@cybernewslive
    Patch

    Google has patched two critical security flaws in Chrome that could let attackers take over your computer just by visiting a website — no download required. One flaw (CVE-2026-9111) could allow full remote code execution on Linux; the other (CVE-2026-9110) could let attackers show you a convincing fake login window on Windows to steal your password. A separate unpatched flaw called 'Browser Fetch' was accidentally made public in May 2026 and its exploit code is now circulating — that fix is not included in this update. Open Chrome, click the three dots top-right, go to Settings → About Chrome, and let it update to version 148.0.7778.179 — then restart the browser. 💥 #CyberNewsLive https://malwarebytes.com/blog/bugs/2026/05/update-chrome-now-critical-bugs-could-let-attackers-run-code

    Post summary

    Google released patches for CVE-2026-9111 and CVE-2026-9110, while an unpatched ‘Browser Fetch’ flaw with circulating exploit code remains a concern; users are urged to update to version 148.0.7778.179.

    00001105
    2.1K followersView on X
  • AliAlsahad@AliAlsahad
    Patch

    🚨 أطلقت Google تحديثًا عاجلًا لـ Chrome بعد إصلاح 16 ثغرة، بينها ثغرتان مصنفتان Critical وقد تفتحان الباب لتنفيذ شيفرة عن بُعد على الأجهزة المتأثرة. إحدى أخطر الثغرات هي CVE-2026-9111 في WebRTC من نوع Use-After-Free، ويمكن استغلالها عبر صفحة ويب خبيثة للتلاعب بالذاكرة والوصول إلى RCE. والثغرة الثانية CVE-2026-9110 تضرب طبقة الواجهة UI، وقد تُستخدم لتجاوز بعض القيود الأمنية أو لخداع المستخدم عبر عناصر متصفح مزيفة. التحديث وصل إلى الإصدار 148.0.7778.178/179 على Windows وMac، وإلى 148.0.7778.178 على Linux، مع طرح تدريجي خلال الأيام القادمة. افتح chrome://settings/help، تأكد من التحديث، ثم أعد تشغيل المتصفح، لأن مجرد التأخير هنا يترك المتصفح في مواجهة ثغرات عالية الخطورة.

    Post summary

    Google released an emergency Chrome update to patch 16 vulnerabilities, including the critical CVE‑2026‑9111 (Use‑After‑Free RCE via malicious WebRTC) and CVE‑2026‑9110 (UI layer bypass). Users should immediately update through chrome://settings/help to mitigate the high‑severity risks.

    0000069
    77 followersView on X
  • めんたいの、めんたいによる、めんたいのためのめんたい@d52425
    General

    CVE-2026-9110:Inappropriate implementation in UI(Critical) CVE-2026-9111:Use after free in WebRTC(Critical) きょうもきょうとて・・・

    Post summary

    The post lists two new critical CVEs with brief vulnerability descriptions but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000099
    222 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-9110 Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML pag... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-9110

    Post summary

    The text provides a vulnerability description for CVE-2026-9110, outlining a UI spoofing flaw in Google Chrome that can be triggered by a crafted HTML page when the renderer process is compromised, with no mention of PoC, exploitation, patch, or false positive.

    0000086
    4.0K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more