CVE-2026-7911
8.3Google · Chrome
A use after free vulnerability in Aura in Google Chrome on Windows prior to 148.0.7778.96 allows a remote attacker to perform a sandbox escape via a crafted HTML page.
Executive summary
A high-severity use after free vulnerability in Google Chrome on Windows allows remote attackers to achieve a sandbox escape and potentially execute arbitrary code via a crafted HTML page.
Vulnerability
This flaw is a use after free memory corruption issue (CWE-416) residing in the Aura component of Google Chrome on Windows, requiring user interaction via a malicious web page and an attacker who has already compromised the renderer process, with no prior authentication required.
Business impact
A successful exploit of this vulnerability could allow an attacker to escape the browser sandbox and compromise the underlying operating system, leading to total loss of confidentiality, integrity, and availability. With a CVSS score of 8.3, this high-severity flaw threatens enterprise workstations and user data, making rapid remediation essential to prevent host-level compromise.
Remediation
Immediate Action: Update Google Chrome to version 148.0.7778.96 or later across all Windows endpoints immediately.
Proactive Monitoring: Monitor endpoint detection and response (EDR) telemetry for unusual browser subprocess behavior, unexpected process spawning, or anomalous network connections originating from browser processes.
Compensating Controls: Enforce standard user privilege principles on workstations to limit the impact of a potential sandbox escape, and utilize enterprise browser security policies to restrict navigation to untrusted sites.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Given the high CVSS score and the severe potential impact of a browser sandbox escape, administrators must prioritize updating Google Chrome across all Windows environments. Prompt deployment of the latest stable channel update is critical to neutralize this attack vector before exploitation techniques are developed or weaponized.