CVE-2026-7898Disclosure(google / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch google chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in Chromoting in Google Chrome on Linux prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 3 mentions (2026-05-07); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Products
chromelinux_kernel

1 version affected across 2 products

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-05-07: 3Mentions · 2026-05-14: 1Mentions · 2026-05-15: 1Mentions · 2026-06-08: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-07: 3Technical Details · 2026-05-14: 1Technical Details · 2026-05-15: 1Technical Details · 2026-06-08: 105-0705-1405-1506-08
Signal classification2 categories
Disclosure
350.0%
Patch
350.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-073
Disclosure2Patch1
2026-05-141
Patch1
2026-05-151
Patch1
2026-06-081
Disclosure1
Full discourse6 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🚨 Chrome 148 emergency patch: 3 critical + dozens high-risk memory bugs ... update now. CVE highlights: CVE-2026-7896 (integer overflow in Blink → heap corruption/RCE potential), CVE-2026-7897 (use‑after‑free in Mobile → UAF → sandbox bypass), CVE-2026-7898 (use‑after‑free in Chromoting → remote desktop component RCE/escape); many other high/medium issues affect V8, ANGLE, GPU, Downloads, Tab Groups, Fonts, Skia, WebRTC and more. Hashtags: #Chrome148 #ZeroDay #PatchNow #InfoSec #BrowserSecurity

    Post summary

    The post announces an emergency patch for Chrome 148, listing critical CVEs with detailed vulnerability descriptions, and urges users to update immediately.

    1004192
    1.8K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-7898 – Use-after-free in Chromoting (Chrome Remote Desktop) Severity: Critical Discovered: April 20 (Google internal) Impact: Full browser compromise via drive-by attack Affected: Any user with Chrome Remote Desktop active

    Post summary

    A critical use-after-free flaw in Chrome Remote Desktop may lead to full browser compromise via drive-by attack, but no exploitation or patches are referenced.

    1000059
    258 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Google Chrome 148 がリリース:3件の Critical を含む 127 件の脆弱性を修正 https://iototsecnews.jp/2026/05/07/google-chrome-148-released-with-fix-for-127-security-vulnerabilities-update-now/ 今回のアップデートでは、メモリの管理不備が引き起こす、多くの脆弱性が修正されています。脆弱性 CVE-2026-7897/ CVE-2026-7898/CVE-2026-7901 などに見られる解放後メモリ使用の問題は、一度解放されたはずのメモリ領域に、プログラムが再アクセスすることで発生します。また、 CVE-2026-7896 のような整数オーバーフローや、 CVE-2026-7899 などの境界外読み取り/書き込みといった問題は、データのサイズ確認やアクセス範囲の制限が不十分なことで発生します。 V8 エンジンや ANGLE といった複雑な仕組みの中で、オブジェクトの寿命やデータの境界を正確に制御することの難しさが、これらの脆弱性につながっています。ご利用のチームは、ご注意ください。 #Chrome #Google #Vulnerability

    Post summary

    The article announces a Chrome 148 release that patches 127 vulnerabilities, including three critical CVEs with detailed technical descriptions.

    01000146
    491 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7898 Use after free in Chromoting in Google Chrome on Linux prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromi… https://www.cve.org/CVERecord?id=CVE-2026-7898 ----- Traducción: CVE-2026-7898 Uso… http://infoflow.cloud`

    Post summary

    The message announces CVE‑2026‑7898, a use‑after‑free vulnerability in Chrome’s Chromoting component on Linux that allows remote code execution before version 148.0.7778.96.

    0000041
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7898 Use after free in Chromoting in Google Chrome on Linux prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromi… https://www.cve.org/CVERecord?id=CVE-2026-7898

    Post summary

    The text announces CVE‑2026‑7898, detailing a use‑after‑free flaw in Chrome’s Chromoting component on Linux that could lead to remote code execution via malicious traffic.

    00000179
    57.4K followersView on X
  • Geek@geek_of_life
    Patch

    Google corrige 127 vulnérabilités, mais 3 critiques. CVE-2026-7898 – Use-after-free in Chromoting (Chrome Remote Desktop) CVE-2026-7897 – Use-after-free in Mobile CVE-2026-7896 – Integer overflow in Blink (moteur de rendu) Le principal serait des bugs mineurs. #cyber #bug

    Post summary

    Google issued patches for 127 vulnerabilities, including three use‑after‑free and integer overflow bugs; the post does not mention PoCs, exploits, or active exploitation.

    00000107
    113 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---
OSlinuxlinux_kernel---

Explore more