CVE-2026-7984
8.8Google · Chrome
A use-after-free vulnerability in ReadingMode within Google Chrome prior to version 148.0.7778.96 allows remote attackers to execute arbitrary code via a crafted HTML page.
Executive summary
A use-after-free vulnerability in Google Chrome prior to version 148.0.7778.96 permits remote code execution via a crafted HTML page, presenting a critical risk to endpoint security.
Vulnerability
This is a use-after-free vulnerability classified under CWE-416, occurring within the ReadingMode component. An unauthenticated remote attacker who has compromised the renderer process can exploit this flaw using a crafted HTML page to execute arbitrary code within the sandbox.
Business impact
A successful exploit of this vulnerability could lead to total compromise of the browser session and potential escalation from the compromised renderer process. This poses significant risks of data theft, user session hijacking, and potential host system compromise depending on sandbox integrity. The high CVSS score of 8.8 justifies treating this issue with high urgency to protect enterprise endpoints.
Remediation
Immediate Action: Update Google Chrome to version 148.0.7778.96 or later across all managed endpoints.
Proactive Monitoring: Monitor endpoint telemetry for anomalous browser crashes, unexpected renderer process terminations, or unauthorized child process spawns.
Compensating Controls: Enforce strict browsing policies and utilize advanced endpoint protection platforms with behavior monitoring to detect and block malicious HTML exploitation attempts.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Organizations must prioritize deploying the Google Chrome security update to version 148.0.7778.96 across all workstations and servers. Given the high potential impact of remote code execution via standard web browsing activities, immediate application of the vendor patch is vital to eliminate exposure.