CVE-2026-7981
8.1Google · Chrome
An out of bounds read in Google Chrome codecs allows remote attackers to obtain sensitive memory information via malicious files.
Executive summary
A critical out of bounds read vulnerability in Google Chrome prior to version 148.0.7778.96 allows unauthenticated remote attackers to obtain sensitive information from process memory.
Vulnerability
This vulnerability is an out of bounds read flaw classified as CWE-125, affecting the browser codecs. An unauthenticated attacker can exploit this via a malicious file requiring user interaction.
Business impact
The exposure of process memory can lead to the leakage of sensitive data, potentially compromising user credentials, session tokens, or internal application states. Although the CVSS score is 8.1, the requirement for user interaction slightly reduces immediate exploitability, but the high confidentiality and integrity impact necessitates swift intervention.
Remediation
Immediate Action: Update Google Chrome to version 148.0.7778.96 or later immediately via the standard update mechanism.
Proactive Monitoring: Monitor client systems for unauthorized browser update delays or anomalous application crash logs related to codec processing.
Compensating Controls: Restrict users from opening untrusted files from external sources until endpoints are fully patched.
Exploitation status
Public Exploit Available: No - no confirmed public exploit or proof of concept is currently available in the tracking data.
Analyst recommendation
Given the high severity rating and potential for sensitive data exposure, security administrators must prioritize updating Google Chrome across all endpoints. Ensure that auto-update policies are enforced to mitigate the risk of exploitation.