CVE-2026-7908Disclosure(apple / chrome)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in Fullscreen in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-15); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-05-07: 1Mentions · 2026-05-15: 3Mentions · 2026-05-18: 1Patch / Workaround · 2026-05-18: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-15: 205-0705-1505-18
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-071
Disclosure1
2026-05-153
Disclosure1General2
2026-05-181
Patch1
Full discourse5 posts
  • S2GRUPO@s2grupo
    Patch

    ‼️Vulnerabilidad crítica en Google Chrome CVE-2026-7908 Recomendaciones: 1. Aplicar el parche oficial 2. Consultar el advisory del fabricante y de CISA 3. Implementar controles compensatorios 4. Revisar inventario de activos Descubre más: https://hubs.la/Q04gcJTc0

    Post summary

    The tweet announces a critical Chrome vulnerability, CVE-2026-7908, and offers patching guidance while providing a link for further details.

    03021241
    5.1K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVSS 9.6 CRITICAL · CVE-2026-7908 · 9.6 → 148.0.7778.96 CVE: CVE-2026-7908 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text provides only basic metadata—CVSS score, severity, and advisory status—without any claim of PoC, exploitation, or mitigation.

    1000051
    215 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-7908 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Use after free in Fullscreen in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a…

    Post summary

    The post announces CVE‑2026‑7908, a critical Chrome sandbox escape vulnerability before version 148.0.7778.96, providing CVSS details and a brief technical description but no PoC, exploit code, or patch information.

    1000054
    215 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7908 Use after free in Fullscreen in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromiu… https://www.cve.org/CVERecord?id=CVE-2026-7908

    Post summary

    CVE-2026-7908 is a use-after-free bug in Chrome’s fullscreen feature that could allow a sandbox escape through a crafted HTML page.

    00010129
    57.4K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-7908-google-chrome #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post merely shares a link to a CVE reference on a website, with no further details or claims about exploitation, patches, or technical specifics.

    0000025
    215 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more