CVE-2026-8000

8.8

Google · Chrome on Windows

Insufficient validation of untrusted input in ChromeDriver in Google Chrome on Windows allows remote code execution via a crafted HTML page.

Executive summary

A high-severity input validation vulnerability in Google Chrome on Windows allows remote code execution via malicious web content.

Vulnerability

This vulnerability is an insufficient validation of untrusted input flaw, classified under CWE-20, affecting the ChromeDriver component. An unauthenticated remote attacker can trigger this issue through user interaction with a crafted HTML page.

Business impact

A successful exploit of this vulnerability could grant an attacker the ability to execute arbitrary code with the privileges of the browser user. This poses severe business risks, including complete system compromise, potential data exfiltration, and operational disruption. The high CVSS score of 8.8 reflects the severity of potential impacts, which include total confidentiality, integrity, and availability losses.

Remediation

Immediate Action: Update Google Chrome on Windows to version 148.0.7778.96 or later as soon as patches are available from the vendor.

Proactive Monitoring: Monitor client systems for anomalous browser behavior, unexpected process creation spawned by the browser, and unauthorized network connections.

Compensating Controls: Restrict web browsing to trusted sites and deploy network defenses to filter malicious HTML content before it reaches endpoints.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Given the high severity score and the potential for complete system compromise, organizations must prioritize updating Google Chrome on Windows across all endpoints. System administrators should verify that auto-update mechanisms function correctly or push out the required version updates immediately to mitigate potential exploitation risks.

More Google CVEs

Sources