CVE-2026-7940 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: May 6, 2026
Google Chrome - Use After Free
Published: May 6, 2026Updated: May 6, 2026Remote Exploitable
Overview
Google Chrome < 148.0.7778.96 contains a use after free caused by improper memory handling in V8 engine, letting attackers who convince users to install malicious extensions execute arbitrary code inside sandbox.
Severity & Score
Severity: High
CVSS Score: 8.8
Impact
Attackers can execute arbitrary code inside the sandbox via malicious Chrome extensions, potentially compromising user data and browser integrity.
Mitigation
Update to version 148.0.7778.96 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-7940
- Severity
- High
- CVSS Score
- 8.8
- Type
- use_after_free
- Status
- confirmed
CWE
- CWE-416
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H