Exploitation Summary
EIP tracks 1 public exploit for CVE-2026-9973. PoCs published by jaf0rk.
AI-analyzed exploit summary This PoC exploits a V8 type confusion vulnerability (CVE-2026-9973) in the Turbofan optimizer's Wasm Load Elimination phase, allowing arbitrary read/write primitives via crafted WebAssembly code. The exploit achieves sandbox escape by corrupting JavaScript object properties and elements pointers.
Description
Out of bounds write in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Exploits (1)
This PoC exploits a V8 type confusion vulnerability (CVE-2026-9973) in the Turbofan optimizer's Wasm Load Elimination phase, allowing arbitrary read/write primitives via crafted WebAssembly code. The exploit achieves sandbox escape by corrupting JavaScript object properties and elements pointers.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H