CVE-2026-9111Patch(apple / chrome)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 11 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 9 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 5 mentions (2026-05-22); latest day: 1
  • 11 total mentions across 6 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline11 mentions / 6d
01345Mentions · 2026-05-20: 1Mentions · 2026-05-21: 2Mentions · 2026-05-22: 5Mentions · 2026-05-23: 1Mentions · 2026-06-05: 1Mentions · 2026-06-09: 1Active Exploitation · 2026-05-22: 1Patch / Workaround · 2026-05-21: 1Patch / Workaround · 2026-05-22: 4Patch / Workaround · 2026-05-23: 1Patch / Workaround · 2026-06-05: 1Technical Details · 2026-05-21: 2Technical Details · 2026-05-22: 5Technical Details · 2026-05-23: 1Technical Details · 2026-06-05: 105-2005-2105-2205-2306-0506-09
Signal classification4 categories
Patch
654.5%
Disclosure
327.3%
Active Exploitation
19.1%
General
19.1%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-201
Disclosure1
2026-05-212
Disclosure1Patch1
2026-05-225
Active Exploitation1Disclosure1Patch3
2026-05-231
Patch1
2026-06-051
Patch1
2026-06-091
General1
Full discourse11 posts
  • Cyber News Live@cybernewslive
    Patch

    Google has patched two critical security flaws in Chrome that could let attackers take over your computer just by visiting a website — no download required. One flaw (CVE-2026-9111) could allow full remote code execution on Linux; the other (CVE-2026-9110) could let attackers show you a convincing fake login window on Windows to steal your password. A separate unpatched flaw called 'Browser Fetch' was accidentally made public in May 2026 and its exploit code is now circulating — that fix is not included in this update. Open Chrome, click the three dots top-right, go to Settings → About Chrome, and let it update to version 148.0.7778.179 — then restart the browser. 💥 #CyberNewsLive https://malwarebytes.com/blog/bugs/2026/05/update-chrome-now-critical-bugs-could-let-attackers-run-code

    Post summary

    The post announces that Google has released critical patches for CVE-2026-9111 and CVE-2026-9110, urging users to update Chrome to 148.0.7778.179 to mitigate remote code execution and phishing risks.

    00001105
    2.1K followersView on X
  • OpSec Insider@OpSecInsider
    Patch

    The WebRTC bug (CVE-2026-9111) is a use-after-free, the class of flaw that powers most real-world browser exploit chains. Both Criticals were found internally by Google on April 20. Patched version: 148.0.7778.178. Restart the browser after updating, that is the step most skip.

    Post summary

    Google discovered a WebRTC use‑after‑free flaw (CVE‑2026‑9111) and released a patch in Chrome 148.0.7778.178; users are advised to update and restart the browser to mitigate potential exploitation.

    1000055
    78 followersView on X
  • Aeden@aedenone
    Patch

    Google just patched 16 Chrome vulnerabilities. The one that matters: CVE-2026-9111, a use-after-free in WebRTC that lets an attacker run code on your machine from a malicious web page. WebRTC is the tech powering browser-based video calls — Google Meet, Zoom web, Teams in browser. It has direct access to your camera, microphone, and network. A use-after-free in that layer means an attacker can corrupt memory and execute code without you downloading anything. Just loading a page is enough. Chrome auto-updates but does not apply until you restart. Check chrome://settings/help — if you are below 148.0.7778.178, restart the browser now. That is the entire fix.

    Post summary

    Google patched CVE-2026-9111, a use‑after‑free in WebRTC that could allow remote code execution from a web page, and urges users to restart Chrome to apply the fix.

    1000058
    122 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Google、Chromeの16件の脆弱性を修正、WebRTCのCVE-2026-9111で任意コード実行の恐れ https://rocket-boys.co.jp/security-measures-lab/chrome-16-vulnerabilities-fixed-cve-2026-9111/ #セキュリティ対策Lab #security #securitynews

    Post summary

    Google has fixed 16 Chrome vulnerabilities, including CVE-2026-9111 which could allow arbitrary code execution via WebRTC. No active exploitation has been reported, and the patch is available.

    00010185
    407 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    CVE-2026-9111 Google Chrome Linux版 148.0.7778.179以前の脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/04/cve-2026-9111-google-chrome-linux-14807778179/ #IT #Security #cybersecurity

    Post summary

    The text is a brief reference to an explanatory article about CVE-2026-9111, with no indication of PoC, exploit code, active exploitation, patches, or technical specifics.

    0000060
    209 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    CVE-2026-9111 Google Chrome Linux版 148.0.7778.179以前の脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/04/cve-2026-9111-google-chrome-linux-14807778179/ #IT #Security #cybersecurity

    Post summary

    The article provides a clear explanation of CVE‑2026‑9111 for Chrome Linux, including vulnerability details and mitigation counters.

    0000064
    209 followersView on X
  • AliAlsahad@AliAlsahad
    Patch

    🚨 أطلقت Google تحديثًا عاجلًا لـ Chrome بعد إصلاح 16 ثغرة، بينها ثغرتان مصنفتان Critical وقد تفتحان الباب لتنفيذ شيفرة عن بُعد على الأجهزة المتأثرة. إحدى أخطر الثغرات هي CVE-2026-9111 في WebRTC من نوع Use-After-Free، ويمكن استغلالها عبر صفحة ويب خبيثة للتلاعب بالذاكرة والوصول إلى RCE. والثغرة الثانية CVE-2026-9110 تضرب طبقة الواجهة UI، وقد تُستخدم لتجاوز بعض القيود الأمنية أو لخداع المستخدم عبر عناصر متصفح مزيفة. التحديث وصل إلى الإصدار 148.0.7778.178/179 على Windows وMac، وإلى 148.0.7778.178 على Linux، مع طرح تدريجي خلال الأيام القادمة. افتح chrome://settings/help، تأكد من التحديث، ثم أعد تشغيل المتصفح، لأن مجرد التأخير هنا يترك المتصفح في مواجهة ثغرات عالية الخطورة.

    Post summary

    The post announces a Chrome security patch that addresses two critical CVEs, CVE-2026-9111 and CVE-2026-9110, and advises users to update to the new versions immediately.

    0000069
    77 followersView on X
  • めんたいの、めんたいによる、めんたいのためのめんたい@d52425
    Disclosure

    CVE-2026-9110:Inappropriate implementation in UI(Critical) CVE-2026-9111:Use after free in WebRTC(Critical) きょうもきょうとて・・・

    Post summary

    The message announces two critical CVEs with concise technical tags, but offers no further details such as PoC, exploit code, active use, or mitigations.

    0000099
    222 followersView on X
  • ThreadLinqs@threadlinqs
    Active Exploitation

    NEW THREAT INTEL: Chrome 148 OOB update - CVE-2026-9111 WebRTC UAF RCE (Critical). 16 CVEs patched, 9 detections. https://intel.threadlinqs.com/#TL-2026-0554 #ThreatIntel #Chrome #CVE https://t.co/TZEF6Ah3Xt

    Post summary

    The tweet reports that Chrome 148 patch addresses CVE‑2026‑9111 and that the vulnerability is currently being exploited, with nine detections noted.

    0000080
    51 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-9111 Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-9111

    Post summary

    The notice discloses CVE-2026-9111, a use‑after‑free vulnerability in WebRTC that allows remote code execution on Chrome Linux before version 148.0.7778.179, with no evidence of PoC, tool, active exploitation, or patch information.

    00000110
    4.0K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Google Chrome (CVE-2026-9111) https://vuldb.com/vuln/364917

    Post summary

    The post announces a new Google Chrome vulnerability (CVE-2026-9111) with higher severity, functioning solely as a disclosure without PoC, exploit, or patch details.

    00000106
    2.2K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more