CVE-2026-9995
Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a
CVSS
8.8
High
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Published: May 28, 2026 · Last modified: Jul 21, 2026 · CWE-416
0.3%EPSS · 30 days0.3%
2026-08-112026-09-07
Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-853607.0 HIG—
———Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.6hCVE-2026-839978.1 HIG—
———Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.6hCVE-2026-839797.8 HIG—
———Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.6hCVE-2026-839687.8 HIG—
———Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.6hCVE-2026-839407.0 HIG—
———Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.6hCVE-2026-819547.8 HIG—
———Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.6h