CVE-2026-7919

8.3

Google · Chrome

A use-after-free vulnerability in the Aura component of Google Chrome prior to version 148.0.7778.96 allows a remote attacker to achieve sandbox escape via a crafted HTML page.

Executive summary

A high-severity use-after-free vulnerability in Google Chrome prior to version 148.0.7778.96 permits a compromised renderer process to escape the security sandbox.

Vulnerability

The flaw is classified as a Use After Free (CWE-416) within the Aura windowing framework of Google Chrome. An unauthenticated attacker who has already compromised the renderer process can leverage this defect via a crafted HTML page with user interaction.

Business impact

A successful exploit allows an adversary to break out of the browser sandbox, potentially leading to arbitrary code execution on the underlying host operating system. This could result in total confidentiality, integrity, and availability compromise of user workstations. The CVSS score of 8.3 reflects the severe technical impact despite the requirement for user interaction and a compromised renderer.

Remediation

Immediate Action: Update Google Chrome to version 148.0.7778.96 or later immediately.

Proactive Monitoring: Monitor endpoint telemetry for anomalous browser subprocess behavior, unexpected child process spawning, or execution of untrusted binaries originating from browser directories.

Compensating Controls: Enforce strict endpoint security policies, including application whitelisting and reduced user privileges, to limit potential fallout from a successful sandbox escape.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Given the severe impact of a sandbox escape, organizations must prioritize updating all browser instances to the patched version promptly. System administrators should push the update automatically through enterprise management tools to minimize the window of exposure.

More Google CVEs

Sources