CVE-2026-7901Disclosure(apple / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in ANGLE in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • macos

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-07); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
chromemacos

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-07: 3Mentions · 2026-05-14: 1Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-07: 3Technical Details · 2026-05-14: 105-0705-14
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-073
Disclosure3
2026-05-141
Patch1
Full discourse4 posts
  • sakura@eternalsakura13
    Disclosure

    @ret2happy [$16000][497724490] High CVE-2026-7901: Use after free in ANGLE. Reported by Syn4pse (@ret2happy) on 2026-03-30 game winner happy

    Post summary

    The tweet announces a high-severity use-after-free vulnerability (CVE-2026-7901) in ANGLE, providing the technical nature of the flaw but no PoC, exploit code, or patch information.

    1103753.5K
    9.3K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Google Chrome 148 がリリース:3件の Critical を含む 127 件の脆弱性を修正 https://iototsecnews.jp/2026/05/07/google-chrome-148-released-with-fix-for-127-security-vulnerabilities-update-now/ 今回のアップデートでは、メモリの管理不備が引き起こす、多くの脆弱性が修正されています。脆弱性 CVE-2026-7897/ CVE-2026-7898/CVE-2026-7901 などに見られる解放後メモリ使用の問題は、一度解放されたはずのメモリ領域に、プログラムが再アクセスすることで発生します。また、 CVE-2026-7896 のような整数オーバーフローや、 CVE-2026-7899 などの境界外読み取り/書き込みといった問題は、データのサイズ確認やアクセス範囲の制限が不十分なことで発生します。 V8 エンジンや ANGLE といった複雑な仕組みの中で、オブジェクトの寿命やデータの境界を正確に制御することの難しさが、これらの脆弱性につながっています。ご利用のチームは、ご注意ください。 #Chrome #Google #Vulnerability

    Post summary

    Google Chrome 148 was released with fixes for 127 vulnerabilities, including several critical memory‑management issues; the post focuses on the patch release and technical details of the bugs.

    01000146
    491 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7901 Use after free in ANGLE in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch… https://www.cve.org/CVERecord?id=CVE-2026-7901 ----- Traducción: CVE-2026-7901 Uso… http://infoflow.cloud`

    Post summary

    CVE-2026-7901 documents a use-after-free flaw in ANGLE on macOS Chrome prior to 148.0.7778.96 that can lead to remote code execution through a crafted HTML page, with no mention of PoC, active exploitation, or patch.

    0000036
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7901 Use after free in ANGLE in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Ch… https://www.cve.org/CVERecord?id=CVE-2026-7901

    Post summary

    CVE-2026-7901 is a use‑after‑free vulnerability in ANGLE impacting Chrome on macOS before version 148.0.7778.96, enabling remote attackers to execute arbitrary code inside a sandbox via crafted HTML.

    00000115
    57.4K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---

Explore more