All findings

CVE-2026-9973 high

Chrome credits OpenAI researcher on V8 out-of-bounds write

Chrome credits amyb of OpenAI on CVE-2026-9973, a High-severity V8 out-of-bounds write that aligns with OpenAI Daybreak's public five-bug Chrome campaign.

Bug class
Out-of-bounds write
Affected codebase
Google Chrome V8
Credited system
OpenAI Daybreak
Disclosed
May 27, 2026
Attribution
Self-reported attribution
Severity
high
Source status: Chrome directly credits amyb of OpenAI and rates the issue High, but does not name an AI system. OpenAI's Daybreak disclosure says its researchers reported five exploitable V8 bugs without enumerating the CVEs, so the campaign mapping is transparent and self-reported rather than a direct Codex credit.

Summary

CVE-2026-9973 is an out-of-bounds write in V8. Chrome rates it High and credits amyb of OpenAI. OpenAI later described five exploitable V8 vulnerabilities as part of its public Daybreak record, but did not publish a per-CVE mapping for that set.

Attribution boundary

The affected-vendor credit establishes the OpenAI researcher and vulnerability. The Daybreak association comes from OpenAI’s campaign-level disclosure, so it is labeled self-reported. This entry does not assign CVE-2026-9973 to Codex Security; Chrome uses that explicit system credit only for CVE-2026-14431.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.