CVE-2026-9120Disclosure(apple / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-20); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-20: 2Mentions · 2026-06-08: 1Patch / Workaround · 2026-06-08: 1Technical Details · 2026-05-20: 1Technical Details · 2026-06-08: 105-2006-08
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-202
Disclosure1General1
2026-06-081
Patch1
Full discourse3 posts
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    CVE-2026-9120 Google Chrome 148.0.7778.179以前の脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/04/cve-2026-9120-google-chrome-14807778179/ #IT #Security #cybersecurity

    Post summary

    The piece offers an explanation of CVE-2026-9120 in Google Chrome, detailing its impact and summarizing available countermeasures, but does not provide a PoC, exploit code, or evidence of active exploitation.

    0001046
    209 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-9120 Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-9120

    Post summary

    The text announces a new CVE (CVE-2026-9120) describing a use‑after‑free flaw in Chrome's WebRTC that permits remote code execution via crafted HTML, with no PoC, exploit code, or patch details mentioned.

    00000104
    4.0K followersView on X
  • VulDB 🛡@vuldb
    General

    The severity is increased for this new vulnerability affecting Google Chrome (CVE-2026-9120) https://vuldb.com/vuln/364934

    Post summary

    The post announces that CVE‑2026‑9120, a newly identified vulnerability affecting Google Chrome, has had its severity increased, but no further technical details, PoC, exploit, or patch information are given.

    0000075
    2.2K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more