Description
Use after free in WebAudio in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-05-06
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Use‑after‑free in WebAudio allows a remote attacker to craft a malicious HTML page that triggers a memory corruption bug, enabling execution of arbitrary code inside Chrome’s sandbox. The flaw is a classic CWE‑416 vulnerability that could give an attacker full control over the victim’s browser process.

Affected Systems

The affected product is Google Chrome on all platforms for versions prior to 148.0.7778.96. Users browsing the web with a vulnerable Chrome installation are at risk.

Risk and Exploitability

The vulnerability has a CVSS score of 8.8 and is classified as Medium severity by Chromium. Because it requires an attacker to embed crafted HTML and the exploitation must happen within the sandbox, the likelihood of real‑world exploitation is moderate. No evidence suggests it is in the CISA KEV catalog or has an EPSS score at this time.

Generated by OpenCVE AI on May 7, 2026 at 00:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 148.0.7778.96 or later, available as the latest stable release
  • If an update cannot be applied immediately, configure Chrome policies to block or disable WebAudio for the affected browsers
  • Ensure automatic updates are enabled so future patches are applied promptly

Generated by OpenCVE AI on May 7, 2026 at 00:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6250-1 chromium security update
History

Thu, 07 May 2026 01:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in WebAudio Enables Remote Code Execution

Wed, 06 May 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Wed, 06 May 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 06 May 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 06 May 2026 20:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in WebAudio Enables Remote Code Execution

Wed, 06 May 2026 18:30:00 +0000

Type Values Removed Values Added
Description Use after free in WebAudio in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-07T03:56:05.831Z

Reserved: 2026-05-05T22:59:26.341Z

Link: CVE-2026-7980

cve-icon Vulnrichment

Updated: 2026-05-06T19:05:09.540Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T19:16:48.860

Modified: 2026-05-06T23:23:40.757

Link: CVE-2026-7980

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T01:00:14Z

Weaknesses