CVE-2026-9931: High Use after free in GPU
Chromium: CVE-2026-9931 Use after free in GPU
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
— NVD
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome / Chromium (GPU)to a version that resolves this vulnerability.Fixed in 148.0.7778.216
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-9931?
CVE-2026-9931 has a high severity rating of 8.3 according to the CVSS 3.1 scoring system.
What does CVE-2026-9931 entail?
CVE-2026-9931 is a use after free vulnerability in the GPU component of Google Chrome that allows for potential remote code execution.
How do I fix CVE-2026-9931?
To mitigate CVE-2026-9931, update Google Chrome or Microsoft Edge to version 148.0.7778.216 or later.
Which software is affected by CVE-2026-9931?
CVE-2026-9931 affects Google Chrome and Microsoft Edge (Chromium-based) versions prior to 148.0.7778.216.
When was CVE-2026-9931 published?
CVE-2026-9931 was published on April 10, 2026.