CVE-2026-7345
8.3Google · Chrome
Google Chrome contains a vulnerability in the Feedback component where insufficient input validation allows a compromised renderer process to perform a sandbox escape via a crafted HTML page.
Executive summary
A high-severity sandbox escape vulnerability in Google Chrome allows remote attackers to break out of the browser security model, posing a significant risk of system compromise.
Vulnerability
This flaw stems from insufficient validation of untrusted input within the Feedback component. An unauthenticated remote attacker who has already compromised the renderer process can leverage this vulnerability to escape the browser sandbox.
Business impact
The ability to escape the browser sandbox represents a critical failure in defense-in-depth, potentially allowing an attacker to execute arbitrary code on the underlying operating system. With a CVSS score of 8.3, this vulnerability poses a high risk to organizational security, as successful exploitation could lead to full system compromise, data exfiltration, or the installation of persistent malware.
Remediation
Immediate Action: Update all Google Chrome installations to version 147.0.7727.138 or later immediately to incorporate the necessary security patches.
Proactive Monitoring: Monitor endpoint security logs for unusual process spawning behavior or unauthorized file system access originating from the Chrome browser process.
Compensating Controls: Ensure that the browser is running with the latest security baseline configurations and that users operate with the principle of least privilege to limit the impact of a potential sandbox escape.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the severity of a sandbox escape, organizations must prioritize the deployment of the Google Chrome update across all managed workstations. Failure to patch allows a compromised renderer process to bypass critical security boundaries, significantly increasing the risk of full system compromise. Patch management teams should treat this update as a high-priority task.