Description
Insufficient data validation in InterestGroups in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-06
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from insufficient data validation in InterestGroups handling code within Google Chrome. An attacker who has already compromised the renderer process can craft a malicious HTML page to exploit this flaw, potentially bypassing the browser’s sandbox protections. This leads to privilege escalation, allowing the attacker to execute code with elevated privileges and compromise the integrity of the host system.

Affected Systems

Affected Chrome installations are not explicitly enumerated in the CVE data. The description mentions "prior to 148.0.7778.96" but does not provide a definitive fix or affected version list. Administrators must consult Google’s Chrome release notes and security advisories to determine which installs remain vulnerable.

Risk and Exploitability

The vulnerability carries a high severity rating, reflected by a CVSS score of 8.3. No EPSS score is available, and the issue is not listed in CISA’s KEV catalog, suggesting no known active exploitation. Leveraging the flaw requires renderer compromise, typically achieved through malicious web content. The sandbox escape directly threatens system integrity, so the risk remains elevated until a vendor patch is applied.

Generated by OpenCVE AI on May 7, 2026 at 03:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Google’s Chrome release page for security updates and upgrade to the latest stable version.
  • Enable Chrome policies that restrict renderer capabilities, such as disabling extensions that bypass sandbox isolation.
  • Apply operating‑system level sandboxing and ensure strict process isolation to limit the damage from any renderer compromise.

Generated by OpenCVE AI on May 7, 2026 at 03:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6250-1 chromium security update
History

Thu, 07 May 2026 04:15:00 +0000

Type Values Removed Values Added
Title Insufficient Data Validation in Chrome InterestGroups Leading to Sandbox Escape

Thu, 07 May 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-79

Thu, 07 May 2026 00:00:00 +0000

Type Values Removed Values Added
Title Insufficient Data Validation in Chrome InterestGroups Leading to Sandbox Escape
Weaknesses CWE-285
CWE-79

Wed, 06 May 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Wed, 06 May 2026 23:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 06 May 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Wed, 06 May 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 06 May 2026 18:30:00 +0000

Type Values Removed Values Added
Description Insufficient data validation in InterestGroups in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-07T03:56:44.558Z

Reserved: 2026-05-05T22:59:08.472Z

Link: CVE-2026-7916

cve-icon Vulnrichment

Updated: 2026-05-06T20:41:05.447Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T19:16:39.880

Modified: 2026-05-06T23:39:52.547

Link: CVE-2026-7916

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T04:00:14Z

Weaknesses