CVE-2026-10015

8.8

Google · Chrome

An integer overflow vulnerability in the WTF (Web Template Framework) library of Google Chrome may lead to memory corruption.

Executive summary

An integer overflow vulnerability in Google Chrome's WTF component poses a high risk of remote code execution through malicious web content.

Vulnerability

This vulnerability is an integer overflow located in the WTF component of Google Chrome. It requires an unauthenticated remote attacker to entice a user into visiting a malicious webpage to trigger the flaw.

Business impact

The integer overflow can be leveraged to bypass security controls or achieve remote code execution, threatening the integrity and confidentiality of the host machine. The CVSS score of 8.8 reflects the high potential for total impact if the vulnerability is successfully exploited by an attacker.

Remediation

Immediate Action: Apply the latest Google Chrome security updates to version 148.0.7778.216 or higher.

Proactive Monitoring: Monitor for abnormal memory usage patterns in browser processes or suspicious redirects within the web environment.

Compensating Controls: Ensure that browser security settings are configured to high-protection modes and deploy endpoint security software to detect malicious payloads.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations should enforce automated browser updates to ensure all workstations are protected against this high-severity vulnerability. Prompt patching is the most effective way to eliminate the risk of exploitation.

More Google CVEs