CVE-2026-7917

8.3

Google · Chrome on Windows

A use-after-free vulnerability in the Fullscreen component of Google Chrome on Windows prior to version 148.0.7778.96 allows sandbox escapes via crafted HTML pages.

Executive summary

A critical use-after-free vulnerability in Google Chrome on Windows enables remote attackers who compromise the renderer process to achieve sandbox escape and total system compromise.

Vulnerability

This flaw is classified as a use-after-free weakness (CWE-416) within the Fullscreen implementation. An unauthenticated attacker requiring user interaction, specifically visiting a crafted HTML page, can trigger memory corruption after compromising the renderer process.

Business impact

The exploitation of this vulnerability can lead to a complete compromise of the underlying operating system environment, bypassing the browser sandbox entirely. Successful attacks result in total confidentiality, integrity, and availability impacts for affected workstations. Given the high CVSS score of 8.3, prompt remediation is required to prevent widespread endpoint compromise within the enterprise.

Remediation

Immediate Action: Update Google Chrome on Windows to version 148.0.7778.96 or later by applying the official vendor security update.

Proactive Monitoring: Monitor endpoint management platforms to track browser version compliance and investigate any anomalous renderer process crashes or unexpected browser behavior.

Compensating Controls: Enforce strict enterprise browsing policies and employ endpoint detection and response solutions to identify unauthorized child process creation resulting from potential browser exploits.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Organizations must prioritize updating Google Chrome across all managed Windows endpoints to neutralize the risk of sandbox escape. Security teams should verify that automatic browser updates are functioning correctly and audit endpoint compliance immediately.

More Google CVEs

Sources