Vulnerabilities · 132 days ago

Google Chrome (Chrome 148, 148.0.7778.96/97) security issue includes CVE-2026-7896

Chrome 148 stable rollout patches 127 vulnerabilities, including critical CVE-2026-7896 (Blink integer overflow) and CVE-2026-7897/7898 (use-after-free in Mobile and Chromoting). CVEs: CVE-2026-7896, CVE-2026-7897, CVE-2026-7898.

CVE-2026-7898

NVD KEV

CVSS 8.8 HIGH: use after free in Chromoting in Google Chrome on Linux prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via malicious network traffic. EPSS 0.3% (22nd percentile). Microsoft patch: Release Notes.

CVE-2026-7897

NVD KEV

CVSS 7.5 HIGH: use after free in Mobile in Google Chrome on iOS prior to 148.0.7778.96 allowed a remote attacker who convinced a… EPSS 0.3% (22nd percentile). Microsoft patch: Release Notes.

CVE-2026-7896

NVD KEV

CVSS 8.8 HIGH: integer overflow in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. EPSS 0.3% (20th percentile). Microsoft patch: Release Notes.

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-05-07

Editions

Related stories