CVE-2026-9872
EPSS 0.4% (31º percentile).
Vulnerabilità ed exploit
Il conteggio degli aggiornamenti di Chrome nasconde il rischio reale: i bug che continuano a trasformarsi in browser takeover restano concentrati nel codice più difficile da verificare. GPU, Network, WebGL e Dawn sono i punti in cui contenuti web non attendibili possono aggirare la memory safety e passare da una pagina al processo del browser.
1 fonte · 29 mag
EPSS 0.4% (31º percentile).
CVSS 8.8 HIGH: use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. EPSS 0.4% (29º percentile). Patch Microsoft: Release Notes.
EPSS 0.3% (25º percentile). Patch Microsoft: Release Notes.
EPSS 0.3% (25º percentile). Patch Microsoft: Release Notes.
EPSS 0.3% (22º percentile). Patch Microsoft: Release Notes.
SecurityWeek
Chrome 148 Update Patches 151 Vulnerabilities
The browser update resolves critical-severity security defects that could potentially lead to remote code execution.
originaleRiepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-05-30
Every edition of this story: La zona ad alto rischio di memory-safety di Chrome riceve un altro grande patch