CVE-2026-7354
8.8Google · Chrome
An out of bounds read and write vulnerability in the Angle component of Google Chrome allows a remote attacker to potentially achieve a sandbox escape via a crafted HTML page.
Executive summary
A high-severity out of bounds memory vulnerability in Google Chrome could permit a remote attacker to escape the browser sandbox, posing a significant risk to system integrity.
Vulnerability
This is an out of bounds read and write vulnerability within the Angle graphics component. It can be triggered by an unauthenticated remote attacker through a maliciously crafted HTML page, potentially leading to a sandbox escape.
Business impact
The ability to escape the browser sandbox represents a critical threat to endpoint security, as it allows attackers to bypass core browser protections and interact directly with the underlying operating system. Given the CVSS score of 8.8, this vulnerability carries a high risk of total system compromise, data exfiltration, or the installation of persistent malware, which could result in severe reputational and operational damage to the organization.
Remediation
Immediate Action: Update all instances of Google Chrome to version 147.0.7727.138 or later immediately to incorporate the vendor security patches.
Proactive Monitoring: Review browser crash logs and security event logs for signs of anomalous memory access or unexpected process termination events that may indicate exploitation attempts.
Compensating Controls: Ensure that endpoint protection software is fully updated to detect and block malicious web content, and consider enforcing strict browser policies that limit the execution of untrusted scripts or plugins.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The severity of this vulnerability, combined with the potential for sandbox escape, necessitates an expedited patching cycle across all enterprise workstations. IT administrators should prioritize the deployment of the latest Chrome update to minimize the attack surface and prevent the possibility of remote code execution or system-level compromise.