CVE-2026-10013

8.8

Google · Chrome

A Use-After-Free vulnerability in the WebCodecs API of Google Chrome could lead to unauthorized code execution.

Executive summary

A critical Use-After-Free flaw in Google Chrome's WebCodecs API exposes users to potential remote code execution via malicious web content.

Vulnerability

This vulnerability is a Use-After-Free error occurring within the WebCodecs API. An unauthenticated attacker can exploit this by directing a user to a specially crafted website to trigger memory corruption.

Business impact

Exploitation of this vulnerability may allow an attacker to execute arbitrary code within the context of the browser, potentially leading to full system compromise. The CVSS score of 8.8 highlights the severity of this issue, necessitating rapid response to protect organizational assets.

Remediation

Immediate Action: Update all Google Chrome installations to version 148.0.7778.216 or later.

Proactive Monitoring: Monitor for unexpected browser process terminations or unusual memory consumption metrics across the enterprise.

Compensating Controls: Use web filtering to prevent access to unverified or malicious domains that could host exploits.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability dictates an immediate update cycle across all managed devices. Security teams should prioritize this patch to neutralize the threat of remote code execution.

More Google CVEs