CVE-2026-7956

8.3

Google · Chrome

A use-after-free vulnerability in Google Chrome navigation allows compromised renderer processes to achieve sandbox escapes via crafted HTML pages.

Executive summary

A high-severity use-after-free vulnerability in Google Chrome navigation allows an attacker who has compromised the renderer process to potentially perform a sandbox escape, posing a severe risk to host integrity.

Vulnerability

This flaw involves a use-after-free weakness within the navigation component, triggered when processing a crafted HTML page. The attacker requires a pre-existing compromise of the renderer process along with user interaction.

Business impact

A successful exploit of this vulnerability could allow an attacker to escape the browser sandbox, potentially leading to arbitrary code execution on the underlying host system. This level of compromise threatens corporate data confidentiality, system integrity, and endpoint availability. The assigned CVSS score of 8.3 reflects the severe technical impact, despite requiring user interaction and a compromised renderer process.

Remediation

Immediate Action: Update Google Chrome to version 148.0.7778.96 or later immediately via the standard update mechanism.

Proactive Monitoring: Monitor endpoint telemetry for anomalous browser subprocess behavior, unexpected process spawning, or crash reports related to memory corruption.

Compensating Controls: Ensure endpoint detection and response solutions are active on all client systems to detect post-exploitation activity if a sandbox escape occurs.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Given the severe impact associated with browser sandbox escapes, organizations must prioritize updating Google Chrome across all endpoints. Applying the vendor security update immediately is the only complete remediation for this memory corruption flaw.

More Google CVEs

Sources