CVE-2026-7928
8.8Google · Chrome
A use-after-free vulnerability in WebRTC in Google Chrome on Windows allows remote code execution via a crafted HTML page.
Executive summary
A use-after-free vulnerability in Google Chrome on Windows allows unauthenticated remote attackers to execute arbitrary code via a crafted HTML page.
Vulnerability
This is a use-after-free weakness in the WebRTC component, triggered when an unauthenticated user with user interaction visits a malicious webpage.
Business impact
A successful exploit allows an attacker to achieve remote code execution inside the browser sandbox, potentially leading to complete system compromise or data theft on the affected workstation. With a CVSS score of 8.8, this vulnerability poses a severe risk to organizational endpoints and requires prompt remediation to prevent user workstation takeover.
Remediation
Immediate Action: Update Google Chrome to version 148.0.7778.96 or later.
Proactive Monitoring: Monitor endpoint detection telemetry for anomalous browser subprocess behavior or unexpected process execution spawned by the browser.
Compensating Controls: Ensure network-level filtering and secure web gateways are active to block known malicious domains and delivery mechanisms for browser exploits.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Administrators must prioritize updating Google Chrome instances across all Windows endpoints to version 148.0.7778.96 or later. Due to the high severity and potential for remote code execution via standard web browsing activities, immediate patch deployment is essential for maintaining endpoint security.