CVE-2026-7957
8.8Google · Chrome
An out of bounds write vulnerability in Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
Executive summary
A critical out of bounds write vulnerability in Google Chrome on Mac and iOS allows remote attackers to execute arbitrary code within the browser sandbox.
Vulnerability
This flaw is an out of bounds write vulnerability (CWE-787) residing in the Media component. An unauthenticated remote attacker with user interaction can exploit this via a crafted HTML page if they have already compromised the renderer process.
Business impact
Successful exploitation of this vulnerability enables a remote attacker to achieve arbitrary code execution within the browser sandbox, potentially leading to full system compromise or sensitive data exfiltration on affected Mac and iOS devices. Although the CVSS score is 8.8, the capability for remote code execution presents a severe risk to organizational endpoints and user privacy.
Remediation
Immediate Action: Update Google Chrome on Mac and iOS to version 148.0.7778.96 or later immediately.
Proactive Monitoring: Monitor endpoint telemetry for unexpected browser crashes or anomalous child process behavior indicative of sandbox escape attempts.
Compensating Controls: Enforce strict browsing policies and utilize advanced endpoint detection and response solutions to identify anomalous renderer process activities.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Given the potential for arbitrary code execution, security teams must prioritize updating Google Chrome across all managed Mac and iOS endpoints. Applying the vendor security update immediately remains the only definitive remediation to secure the browser against this vulnerability.