TopVuln

High-risk vulnerability digests

CVE-2026-7908

  • CRITICAL

Details

CVSS v3
9.6
NVD published
2026-05-06 19:16:39
EPSS
<0.1% probability · 19.4th percentile — 2026-05-11
Affected versions
Google Chrome prior to 148.0.7778.96
Summary
A critical use-after-free flaw exists in the Fullscreen component of Google Chrome before version 148.0.7778.96. A remote attacker can trick a user into opening a crafted HTML page to exploit this issue, potentially achieving a full sandbox escape and arbitrary code execution. Google Chrome is one of the most widely used web browsers globally, making this a high impact flaw for most organizations.
Remediation
Update Google Chrome to version 148.0.7778.96 or newer immediately. Enable automatic browser updates across all organization endpoints. Block access to untrusted web content until all systems are patched.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.