Summary
CVE-2026-9973 is an out-of-bounds write in V8. Chrome rates it High and credits amyb of OpenAI. OpenAI later described five exploitable V8 vulnerabilities as part of its public Daybreak record, but did not publish a per-CVE mapping for that set.
Attribution boundary
The affected-vendor credit establishes the OpenAI researcher and vulnerability. The Daybreak association comes from OpenAI’s campaign-level disclosure, so it is labeled self-reported. This entry does not assign CVE-2026-9973 to Codex Security; Chrome uses that explicit system credit only for CVE-2026-14431.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.