CVE-2026-7914

8.3

Google · Chrome on Windows

A type confusion vulnerability in Accessibility in Google Chrome on Windows prior to 148.0.7778.96 allows sandbox escapes via crafted HTML pages.

Executive summary

A type confusion vulnerability in Google Chrome on Windows allows an attacker who has compromised the renderer process to achieve a sandbox escape.

Vulnerability

This is a type confusion flaw classified under CWE-843, occurring within the Accessibility component and requiring user interaction via a crafted HTML page alongside a prior renderer process compromise.

Business impact

Successful exploitation of this vulnerability can lead to a complete sandbox escape, granting the attacker high privileges on the underlying operating system and risking total system compromise, data loss, and unauthorized access. Given the CVSS score of 8.3, the severity is high, reflecting the potential for severe confidentiality, integrity, and availability impacts if chained with other exploits.

Remediation

Immediate Action: Update Google Chrome on Windows to version 148.0.7778.96 or later immediately.

Proactive Monitoring: Monitor client endpoints for unexpected browser crashes, anomalous child process spawns, or unauthorized system changes following web browsing activities.

Compensating Controls: Restrict web browsing to hardened environments or utilize endpoint protection platforms capable of detecting anomalous renderer process behavior.

Exploitation status

Public Exploit Available: No (false / unknown)

Analyst recommendation

Given the high severity score of 8.3 and the potential for a sandbox escape leading to full system compromise, IT and security administrators must apply the latest Google Chrome updates immediately across all Windows endpoints to mitigate potential risks.

More Google CVEs

Sources