Skip to content
COOEY

EXPOSURES › CVE-2026-9874

CVE-2026-9874

CRITICAL
DETAIL
SourceNVD · cve Published2026-05-28 CVSS9.6 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-9874 ↗

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

AFFECTED FEDRAMP PRODUCTS · 6
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized