Description
Out of bounds memory access in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-06
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds memory access flaw in the V8 JavaScript engine of Google Chrome allows a remote attacker to craft a malicious HTML page that, when rendered, can trigger arbitrary code execution inside the browser sandbox. The vulnerability can be exploited from a remote source and leads to the execution of arbitrary code with the privileges of the browser process, potentially compromising the system through privilege escalation, data exfiltration, or further lateral movement.

Affected Systems

All versions of Google Chrome that have not yet received a V8 update are affected. Specific version details are not provided in the CVE data. The flaw is limited to desktop installations that use the V8 JavaScript engine.

Risk and Exploitability

The CVSS score is 8.8, indicating a high severity vulnerability. No EPSS score is available, and it is not listed in the CISA KEV catalog. The exploit is remote and requires delivery of a crafted HTML page to the victim’s browser; the attacker need not have local access beyond being able to host or embed the malicious content. While the browser’s sandbox can mitigate some damage, the flaw already allows escape into the sandboxed process, so the risk remains significant. Given the absence of a publicly known proof‑of‑concept, the likelihood of exploitation is uncertain but the potential impact is severe.

Generated by OpenCVE AI on May 7, 2026 at 00:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to the latest available version as soon as possible.
  • If an upgrade is not immediately feasible, restrict JavaScript execution or disable V8 features through browser policy until the fix is installed.
  • Apply content‑security policies that block or sanitize untrusted HTML content to prevent delivery of malicious pages.

Generated by OpenCVE AI on May 7, 2026 at 00:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6250-1 chromium security update
History

Thu, 07 May 2026 01:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Memory Access in Chrome V8 Allows Remote Code Execution

Wed, 06 May 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Wed, 06 May 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 06 May 2026 21:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Memory Access in Chrome V8 Allows Remote Code Execution
Weaknesses CWE-787

Wed, 06 May 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 06 May 2026 18:30:00 +0000

Type Values Removed Values Added
Description Out of bounds memory access in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-07T03:56:06.918Z

Reserved: 2026-05-05T22:59:04.817Z

Link: CVE-2026-7902

cve-icon Vulnrichment

Updated: 2026-05-06T20:25:50.348Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T19:16:38.503

Modified: 2026-05-06T23:42:32.560

Link: CVE-2026-7902

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T00:45:16Z

Weaknesses