CVE-2026-7353

8.3

Google · Chrome

A heap buffer overflow in the Skia graphics library allows a remote attacker to achieve a sandbox escape through a crafted HTML page.

Executive summary

A heap buffer overflow vulnerability in Google Chrome allows remote attackers to escape the browser sandbox, posing a severe risk to system integrity.

Vulnerability

This is a heap buffer overflow (CWE-122) within the Skia library. A remote attacker who has already compromised the renderer process can trigger this flaw via a crafted HTML page to perform a sandbox escape.

Business impact

The ability to escape the browser sandbox allows an attacker to bypass critical security boundaries, potentially leading to full system compromise. With a CVSS score of 8.3, this vulnerability represents a high risk that could result in unauthorized data access, malware installation, or persistent system control by an adversary.

Remediation

Immediate Action: Update Google Chrome to version 147.0.7727.138 or later immediately to resolve the vulnerable Skia implementation.

Proactive Monitoring: Monitor browser-related crash logs and security event logs for signs of anomalous renderer process behavior or unexpected sandbox violations.

Compensating Controls: Ensure that endpoint protection software is active and configured to detect malicious process injection attempts or suspicious file system activity originating from browser processes.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a significant risk due to its potential to facilitate a sandbox escape and subsequent system compromise. Security teams should prioritize the deployment of the latest Chrome security updates across all workstations to ensure the vulnerability is patched. Failure to update leaves endpoints exposed to potential exploitation via malicious web content.

More Google CVEs

Sources