CVE-2026-9961

8.8

Google · Chrome

A use-after-free vulnerability in the SurfaceCapture component of Google Chrome allows remote attackers to trigger memory corruption and potentially execute arbitrary code.

Executive summary

Google Chrome versions prior to 148 are vulnerable to a use-after-free defect in SurfaceCapture that could lead to remote code execution.

Vulnerability

This is a use-after-free vulnerability located within the SurfaceCapture functionality. Successful exploitation requires user interaction to visit a malicious page, at which point the attacker can leverage the memory flaw to gain unauthorized control.

Business impact

The flaw poses a significant risk to organizational endpoints, potentially allowing attackers to gain full control over the user session. With a CVSS score of 8.8, this vulnerability is critical for environments where users frequently access untrusted web content.

Remediation

Immediate Action: Update all Google Chrome installations to version 148.0.7778.216 or later as soon as possible.

Proactive Monitoring: Review endpoint security logs for signs of anomalous memory usage or unauthorized process execution associated with the Chrome process.

Compensating Controls: Deploy browser isolation technologies or web filtering tools to restrict access to potentially malicious domains until patching is complete.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The urgency of this update is high due to the potential for remote code execution. Security teams should mandate the update to the latest Chrome release to ensure users are protected against this class of memory-based attacks.

More Google CVEs