CVE-2026-9118Patch(apple / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-05-20); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-20: 2Mentions · 2026-06-05: 1Mentions · 2026-06-08: 1Mentions · 2026-06-09: 1Patch / Workaround · 2026-06-05: 1Patch / Workaround · 2026-06-08: 1Patch / Workaround · 2026-06-09: 1Technical Details · 2026-05-20: 1Technical Details · 2026-06-05: 1Technical Details · 2026-06-08: 1Technical Details · 2026-06-09: 105-2006-0506-0806-09
Signal classification2 categories
Patch
360.0%
Disclosure
240.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-202
Disclosure2
2026-06-051
Patch1
2026-06-081
Patch1
2026-06-091
Patch1
Full discourse5 posts
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    CVE-2026-9118 Google Chrome Windows版(バージョン148.0.7778.179以前)の脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/04/cve-2026-9118-google-chrome-windows14807778179/ #IT #Security #cybersecurity

    Post summary

    A Japanese article explains CVE-2026-9118 in Google Chrome for Windows, covering technical details of the vulnerability, its impact scope, and providing patch or mitigation measures.

    0001064
    209 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    CVE-2026-9118 Google Chrome Windows版(バージョン148.0.7778.179以前)の脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/04/cve-2026-9118-google-chrome-windows14807778179/ #IT #Security #cybersecurity

    Post summary

    The linked article explains the Google Chrome CVE‑2026‑9118 affecting Windows versions prior to 148.0.7778.179, outlines technical details of the vulnerability, and provides countermeasures/patch information, but does not mention active exploitation or a PoC.

    0000035
    209 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    CVE-2026-9118 Google Chrome Windows版(バージョン148.0.7778.179以前)の脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/04/cve-2026-9118-google-chrome-windows14807778179/ #IT #Security #cybersecurity

    Post summary

    The article provides a detailed explanation of CVE-2026-9118, including its impact on older Chrome versions and offers patch and mitigation guidance, but does not mention a PoC, exploit, or active exploitation.

    0000049
    209 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-9118 Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-9118

    Post summary

    A use‑after‑free vulnerability (CVE‑2026‑9118) in Google Chrome’s XR module on Windows permits arbitrary code execution through a crafted HTML page. No active exploitation, patch, or PoC is reported.

    0000068
    4.0K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Google Chrome (CVE-2026-9118) https://vuldb.com/vuln/364933

    Post summary

    The post announces that a severe vulnerability (CVE‑2026‑9118) has been disclosed for Google Chrome, but provides no further technical details, PoC, or evidence of exploitation.

    0000080
    2.2K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more