CVE-2026-9897: High Use after free in DOM
Chromium: CVE-2026-9897 Use after free in DOM
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
— NVD
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 148.0.7778.216
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-9897?
The severity of CVE-2026-9897 is rated high with a CVSS score of 8.8.
How do I fix CVE-2026-9897?
To fix CVE-2026-9897, update Google Chrome to version 148.0.7778.216 or later.
What is the impact of CVE-2026-9897?
CVE-2026-9897 can lead to remote code execution due to a use after free vulnerability in the DOM.
Which software is affected by CVE-2026-9897?
CVE-2026-9897 affects Google Chrome and Microsoft Edge (Chromium-based) versions prior to the fix.
Who reported CVE-2026-9897?
CVE-2026-9897 was reported by the Chrome security team.