CVE-2026-7921

8.8

Google · Chrome

A use-after-free vulnerability in Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

A high-severity use-after-free vulnerability in Google Chrome allows remote attackers to achieve arbitrary code execution through crafted web content.

Vulnerability

This flaw is classified as a Use After Free (CWE-416) within the Passwords component, triggered when an unauthenticated attacker entices a user to visit a malicious HTML page requiring user interaction.

Business impact

A successful exploit could allow an attacker to execute arbitrary code with the privileges of the browser process, leading to complete system compromise or sensitive data theft. Given the high CVSS score of 8.8, organizations face significant risk of endpoint compromise and subsequent lateral movement if users browse to untrusted sites.

Remediation

Immediate Action: Update Google Chrome to version 148.0.7778.96 or later immediately.

Proactive Monitoring: Monitor endpoint detection and response logs for anomalous browser behavior or unexpected child process generation originating from the Chrome executable.

Compensating Controls: Enforce secure browsing policies and utilize web gateway security tools to filter out known malicious domains and untrusted HTML content.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Administrators must prioritize updating all browser instances across the enterprise to the patched version. Prompt deployment of this update is critical to eliminating the remote code execution vector presented by this vulnerability.

More Google CVEs

Sources