CVE-2026-9995: Use after free in WebXR
Chromium: CVE-2026-9995 Use after free in WebXR
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
— NVD
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome / Chromium (WebXR)to a version that resolves this vulnerability.Fixed in 148.0.7778.216 - Compensating control
If immediate upgrade is not possible, mitigate exploitation by preventing untrusted/unknown HTML pages from being rendered in the browser (e.g., restrict browsing to trusted content/sites) to avoid a crafted HTML page triggering the WebXR use-after-free.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-12034
- CVE-2026-7922
- CVE-2026-13033
- CVE-2026-9970
- CVE-2026-10969
- CVE-2026-10003
- CVE-2026-9933
- CVE-2026-9993
- CVE-2026-9961
- CVE-2026-12439
- CVE-2026-10905
- CVE-2026-8557
- CVE-2026-9903
- CVE-2026-7339
- CVE-2026-8559
- CVE-2026-6920
- CVE-2026-8524
- CVE-2026-10007
- CVE-2026-12008
- CVE-2026-12440
- CVE-2026-6360
- CVE-2026-12441
- CVE-2026-7348
Frequently Asked Questions
What is the severity of CVE-2026-9995?
CVE-2026-9995 has a high severity rating of 8.8 according to the CVSS 3.1 scoring system.
What types of vulnerabilities are associated with CVE-2026-9995?
CVE-2026-9995 is associated with a use after free vulnerability in WebXR in Google Chrome.
How does CVE-2026-9995 impact Google Chrome users?
CVE-2026-9995 allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
How do I fix CVE-2026-9995?
To fix CVE-2026-9995, users should update Google Chrome to version 148.0.7778.216 or later.
When was CVE-2026-9995 published?
CVE-2026-9995 was published on May 14, 2026.