CVE-2026-7359
8.8Google · Chrome
A use-after-free vulnerability in the ANGLE component of Google Chrome allows a remote attacker to achieve a sandbox escape via a crafted HTML page.
Executive summary
A critical use-after-free vulnerability in Google Chrome's ANGLE component enables remote attackers to escape the browser sandbox and potentially compromise the underlying system.
Vulnerability
This flaw is a use-after-free vulnerability (CWE-416) within the ANGLE graphics engine, triggered when a user visits a specially crafted HTML page. The attacker requires no prior authentication to trigger the flaw, though the exploit relies on the user interacting with malicious content.
Business impact
The ability to escape the browser sandbox represents a severe security failure, as it allows attackers to bypass core isolation mechanisms designed to protect the operating system from malicious web content. With a CVSS score of 8.8, this high-severity vulnerability poses a significant risk of remote code execution, which could lead to complete system compromise, data theft, or the installation of persistent malware.
Remediation
Immediate Action: Update all instances of Google Chrome to version 147.0.7727.138 or later immediately to incorporate the necessary security patches.
Proactive Monitoring: Monitor endpoint security logs for unusual process creation events or unexpected crashes of the Chrome renderer process, which may indicate attempted exploitation.
Compensating Controls: While no direct virtual patch exists, ensure that endpoint protection platforms are configured to block suspicious browser-based process spawning and enforce restricted user privileges for standard workstations.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score and the nature of the vulnerability as a sandbox escape, prompt remediation is essential. IT administrators should prioritize the deployment of the latest Chrome browser updates across the entire enterprise environment to mitigate the risk of remote exploitation.