CVE-2026-7995

8.8

Google · Chrome

An out-of-bounds read vulnerability in Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

An out-of-bounds read vulnerability in the AdFilter component of Google Chrome prior to version 148.0.7778.96 permits remote code execution within a sandbox via a crafted HTML page.

Vulnerability

This flaw involves an out-of-bounds read (CWE-125) within the AdFilter feature, triggered by unauthenticated remote attackers utilizing a crafted HTML page that requires user interaction.

Business impact

A successful exploit allows attackers to execute arbitrary code within the browser sandbox, which can compromise user sessions, lead to data theft, or facilitate further local exploitation. Although the CVSS score is 8.8, the requirement for user interaction keeps exploitation moderately complex while still presenting severe potential consequences to client endpoints.

Remediation

Immediate Action: Update Google Chrome to version 148.0.7778.96 or later immediately.

Proactive Monitoring: Monitor client endpoints for anomalous browser crashes or unauthorized child process spawns that could indicate sandbox escape attempts.

Compensating Controls: Enforce secure web gateway policies to block navigation to untrusted or newly registered domains that may host malicious HTML pages.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high severity of browser-based arbitrary code execution flaws, organizations must prioritize deploying the latest stable channel update for Google Chrome across all managed client workstations. Promptly patching endpoints neutralizes the out-of-bounds read vector before malicious HTML content can be weaponized in the wild.

More Google CVEs

Sources