CVE-2026-7975

8.3

Google · Chrome

A use after free vulnerability in Google Chrome DevTools allows a remote attacker to potentially perform a sandbox escape.

Executive summary

A use after free vulnerability in Google Chrome DevTools prior to version 148.0.7778.96 allows remote attackers to potentially escape the browser sandbox and compromise the host system.

Vulnerability

This is a Use After Free flaw (CWE-416) within the DevTools component, triggered when an unauthenticated remote attacker entices a user to visit a crafted HTML page after the renderer process has already been compromised.

Business impact

A successful exploit of this vulnerability could lead to complete system compromise, allowing attackers to break out of the browser sandbox and execute arbitrary code on the underlying operating system. Given the CVSS score of 8.3, the potential for total technical impact on confidentiality, integrity, and availability presents a severe risk to organizational endpoints and user data.

Remediation

Immediate Action: Update Google Chrome to version 148.0.7778.96 or later by applying the official vendor security update immediately.

Proactive Monitoring: Monitor browser deployment inventories to ensure outdated versions are identified and remediated across all corporate endpoints.

Compensating Controls: Restrict web browsing activities on critical systems or utilize enterprise browser security policies to minimize exposure to untrusted HTML pages.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Organizations must prioritize updating Google Chrome instances across all environments to eliminate the risk of sandbox escapes. Applying the vendor patch promptly remains the most critical step to prevent potential remote code execution via compromised browser sessions.

More Google CVEs

Sources