CVE-2026-7973
8.8Google · Chrome on Windows
An integer overflow vulnerability in Dawn within Google Chrome on Windows prior to version 148.0.7778.96 allows remote attackers to perform a sandbox escape.
Executive summary
An integer overflow vulnerability in Dawn within Google Chrome on Windows allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page, presenting a high severity risk to endpoint security.
Vulnerability
This vulnerability is an integer overflow flaw, categorized under CWE-472, occurring in the Dawn component of Google Chrome. Exploitation requires user interaction via a crafted HTML page with an unauthenticated remote attacker vector.
Business impact
A successful exploit of this integer overflow can lead to a complete sandbox escape, granting the attacker unauthorized control over the underlying operating system environment. This creates severe risks of data compromise, malware installation, and organizational downtime. The high CVSS score of 8.8 reflects the severity of potential total technical impact involving confidentiality, integrity, and availability.
Remediation
Immediate Action: Update Google Chrome on Windows to version 148.0.7778.96 or later as provided by the vendor.
Proactive Monitoring: Monitor endpoint security logs for unexpected process execution or anomalous browser behavior indicative of sandbox escape attempts.
Compensating Controls: Enforce secure browsing policies and employ endpoint detection and response solutions to identify and block suspicious HTML rendering activities or child process creations.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the severe nature of sandbox escape vulnerabilities and the high CVSS score of 8.8, administrators must treat this advisory with urgency. Apply the necessary browser updates across all Windows endpoints immediately to protect systems against potential remote exploitation.