LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-7940 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: May 6, 2026

Google Chrome - Use After Free

Published: May 6, 2026Updated: May 6, 2026Remote Exploitable

Overview

Google Chrome < 148.0.7778.96 contains a use after free caused by improper memory handling in V8 engine, letting attackers who convince users to install malicious extensions execute arbitrary code inside sandbox.

Severity & Score

Severity: High
CVSS Score: 8.8

Impact

Attackers can execute arbitrary code inside the sandbox via malicious Chrome extensions, potentially compromising user data and browser integrity.

Mitigation

Update to version 148.0.7778.96 or later.

Details

CVE ID
CVE-2026-7940
Severity
High
CVSS Score
8.8
Type
use_after_free
Status
confirmed

CWE

  • CWE-416

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H