CVE-2026-7923

8.3

Google · Chrome

An out of bounds write vulnerability in Skia in Google Chrome prior to 148.0.7778.96 allows a remote attacker to perform a sandbox escape.

Executive summary

An out of bounds write flaw in Google Chrome prior to version 148.0.7778.96 enables a remote attacker who has compromised the renderer process to achieve a sandbox escape and full system compromise.

Vulnerability

This is an out of bounds write vulnerability (CWE-787) residing in the Skia graphics library. An unauthenticated remote attacker with user interaction via a crafted HTML page can leverage this flaw after compromising the renderer process.

Business impact

A successful exploit of this vulnerability can lead to a complete compromise of the underlying host operating system by breaking out of the browser sandbox. This creates significant business risk, including potential data theft, unauthorized lateral movement within the network, and severe system downtime. The CVSS score of 8.3 indicates high severity, reflecting the potential for total loss of confidentiality, integrity, and availability.

Remediation

Immediate Action: Update Google Chrome to version 148.0.7778.96 or later by applying the official vendor security update.

Proactive Monitoring: Monitor endpoint detection and response telemetry for anomalous browser subprocess behavior or unexpected operating system command execution originating from the browser process.

Compensating Controls: Ensure that users operate with the principle of least privilege, restricting standard user accounts from installing unauthorized software or accessing sensitive system areas.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Given the high CVSS score and the severe consequence of a sandbox escape, organizations must prioritize applying the latest Google Chrome updates across all endpoints. Prompt patch deployment is critical to neutralize the risk of complete host compromise via crafted web content.

More Google CVEs

Sources