CVE-2026-9923

8.8

Google · Chrome

A use-after-free vulnerability exists in the Skia graphics library within Google Chrome prior to version 148.0.7778.216, which could lead to arbitrary code execution.

Executive summary

A critical use-after-free vulnerability in the Google Chrome Skia library poses a significant risk of remote code execution via malicious web content.

Vulnerability

This is a use-after-free (CWE-416) vulnerability in the Skia graphics engine. An unauthenticated remote attacker can trigger this flaw by enticing a user to visit a malicious website, leading to memory corruption.

Business impact

The ability for an attacker to achieve code execution through the browser presents a severe risk to organizational data and system integrity. With a CVSS score of 8.8, this vulnerability represents a high-priority threat that could lead to full system compromise if leveraged successfully.

Remediation

Immediate Action: Update all Google Chrome instances to version 148.0.7778.216 or later as soon as possible.

Proactive Monitoring: Review security logs for suspicious browser behavior or unexpected process termination that might signal memory corruption attempts.

Compensating Controls: Utilize modern browser security features and endpoint protection platforms to block known malicious domains and detect anomalous process activity.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Maintaining browser security is essential for defense-in-depth strategies. Promptly applying the vendor-supplied update is the most effective way to eliminate this risk, and administrators should ensure all managed Chrome instances are updated to the current stable release.

More Google CVEs