Description
Use after free in SVG in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-28
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw in the SVG rendering engine of Google Chrome, which allows a remote attacker to execute arbitrary code within the browser’s sandbox when a user opens a specially crafted HTML page. The flaw arises from improper memory handling during SVG parsing, enabling an attacker to trigger the use‑after‑free condition. In practice, an attacker could load malicious content in a browser session and cause the sandboxed process to execute attacker‑supplied code. This risk is classified as high due to the remote nature of the attack and the potential impact on system security.

Affected Systems

Google Chrome browsers running any version prior to 148.0.7778.216 are affected. The issue exists across all supported platforms—including Windows, macOS, Linux, and Chrome OS—whenever the SVG engine is active and the user navigates to or renders a malicious HTML document containing exploitable SVG content.

Risk and Exploitability

The vulnerability can be exploited remotely by an attacker who convinces a user to visit a malicious web page. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog, but its CVSS score of 8.8 and remote execution potential warrant significant concern. Exploitation requires no special network privileges beyond normal browser access, and success would be confined to the sandboxed process. The attackers rely on crafted SVG within an HTML page and the victim’s interaction with that page, making social engineering a likely component of an attack chain.

Generated by OpenCVE AI on May 29, 2026 at 13:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to the latest stable release (148.0.7778.216 or newer).
  • Enable automatic updates to ensure future patches are applied promptly.
  • Configure browser or system policies to block or disable SVG rendering on untrusted sites, if such controls are available.

Generated by OpenCVE AI on May 29, 2026 at 13:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 14:15:00 +0000

Type Values Removed Values Added
Title Use after Free in SVG Allows Remote Code Execution in Google Chrome

Fri, 29 May 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Important


Fri, 29 May 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 28 May 2026 23:45:00 +0000

Type Values Removed Values Added
Title Use after Free in SVG Allows Remote Code Execution in Google Chrome
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 28 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Use after free in SVG in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-30T03:55:23.612Z

Reserved: 2026-05-28T17:25:12.913Z

Link: CVE-2026-10007

cve-icon Vulnrichment

Updated: 2026-05-29T10:17:10.813Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-28T23:16:42.533

Modified: 2026-05-29T12:16:25.147

Link: CVE-2026-10007

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-10007 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T14:00:20Z

Weaknesses