CVE-2026-7920

8.3

Google · Chrome

A use-after-free vulnerability in the Skia component of Google Chrome prior to version 148.0.7778.96 allows a compromised renderer process to achieve a sandbox escape.

Executive summary

A use-after-free vulnerability in Google Chrome prior to version 148.0.7778.96 allows a remote attacker to achieve a sandbox escape, posing a severe risk to host system integrity.

Vulnerability

This vulnerability is a use-after-free flaw (CWE-416) within the Skia graphics library, triggered when a remote attacker who has already compromised the renderer process uses a crafted HTML page to execute a sandbox escape. The attack requires user interaction via the opening of a malicious web page.

Business impact

A successful exploit of this vulnerability could allow an attacker to break out of the browser sandbox, potentially granting them the ability to execute arbitrary code with the privileges of the logged-in user on the underlying operating system. With a CVSS score of 8.3, this high severity flaw threatens complete system confidentiality, integrity, and availability, which could lead to widespread corporate data compromise and severe operational disruption.

Remediation

Immediate Action: Update Google Chrome to version 148.0.7778.96 or later immediately via the standard update mechanism.

Proactive Monitoring: Monitor endpoint security alerts for unusual browser process behavior or unauthorized child process spawns originating from the browser.

Compensating Controls: Restrict web browsing to trusted sites and enforce security policies that limit user interaction with untrusted content if patching is delayed.

Exploitation status

Public Exploit Available: No — As of May 8, 2026, there is no confirmed public exploit or active exploitation in the wild.

Analyst recommendation

Given the high severity score of 8.3 and the potential for a complete sandbox escape, organizations must treat this update with urgency. Deploy the latest version of Google Chrome across all endpoints immediately to protect against potential exploitation chains.

More Google CVEs

Sources