CVE-2026-7901

Google · Chrome

A Use-After-Free vulnerability in the ANGLE graphics engine of Google Chrome on Mac allows for potential arbitrary code execution.

Executive summary

A high-severity Use-After-Free vulnerability in Google Chrome's ANGLE component on Mac could allow a remote attacker to execute arbitrary code.

Vulnerability

The vulnerability is a Use-After-Free flaw within the ANGLE graphics engine. An attacker could exploit this by enticing a user to visit a malicious website, leading to memory corruption and potential code execution.

Business impact

Successful exploitation could allow an attacker to gain control over the browser process on Mac systems, potentially leading to data exfiltration or further system compromise. The CVSS score of 8.8 reflects the high danger of this flaw, as it targets a critical graphics rendering component used by the browser.

Remediation

Immediate Action: Update Google Chrome on all Mac systems to version 148 or later immediately.

Proactive Monitoring: Monitor for browser-related crashes or unexpected spikes in CPU/GPU usage which may indicate exploitation attempts.

Compensating Controls: Maintain updated endpoint security software on all Mac devices to detect and block malicious payloads associated with browser exploitation.

Exploitation status

Public Exploit Available: false

Analyst recommendation

This vulnerability represents a significant risk to Mac users in the enterprise. Security teams must enforce immediate updates to the latest version of Chrome to ensure protection against potential exploitation of the ANGLE component.