CVE-2026-9997
HIGH 8.3EPSS 0.2%
Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- CVSS v3.1
- 8.3 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H - EPSS
- 0.18% chance of exploitation in the next 30 days, 7th percentile
- Published
- 2026-05-28
- Updated
- 2026-05-30
Proof-of-concept exploits (1)
- George0Papasotiriou/CVE-2026-9997-VPN-Split-Tunneling-Bypass-via-DHCP-Option-Injection0★ · 2026-08-03