CVE-2026-7992Disclosure(google / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Insufficient validation of untrusted input in UI in Google Chrome on Linux, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • chrome_os
  • linux_kernel

Threat summary

  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-05-30)
  • 6 total mentions across 5 days

Affected systems

Products
chromechrome_oslinux_kernel

1 version affected across 3 products

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Mentions · 2026-05-12: 1Mentions · 2026-05-22: 1Mentions · 2026-05-30: 2Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-22: 105-0605-0705-1205-2205-30
Signal classification2 categories
Disclosure
350.0%
General
350.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-061
Disclosure1
2026-05-071
General1
2026-05-121
Disclosure1
2026-05-221
Disclosure1
2026-05-302
General2
Full discourse6 posts
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【脆弱性情報】 CVE-2026-7992 Google Chromeの脆弱性について https://www.cybernote.click/2026/05/21/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-7992-google-chrome%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/ #IT #Security #cybersecurity

    Post summary

    The post announces CVE‑2026‑7992 for Google Chrome but provides no PoC, exploit details, patch information, or technical specifics.

    0001061
    209 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【脆弱性情報】 CVE-2026-7992 Google Chromeの脆弱性について https://www.cybernote.click/2026/05/21/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-7992-google-chrome%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/ #IT #Security #cybersecurity

    Post summary

    The post simply cites CVE-2026-7992 and provides a link to an external article; no detailed information on exploitation, patching, or technical aspects is present.

    0000047
    209 followersView on X
  • Ze3ter@ze3ter_
    Disclosure

    nobody audits Chrome's Linux UI code as hard as the renderer CVE-2026-7992 sanitization bypass in Views (the non-Windows UI toolkit) → sandbox escape the attack surface is there, it's just not where everyone is looking

    Post summary

    The post discloses a sanitization bypass in Chrome’s Linux UI toolkit (Views) that can enable sandbox escape, but offers no PoC, exploit details, patch, or evidence of active exploitation.

    0000063
    51 followersView on X
  • K12Tech.com@K12Tech
    Disclosure

    The Data Stream | CVE-2026-7992 in the Chrome OS could allow an attacker to take control of a district Chromebook if a student visits a malicious website. https://newsletter.k12tech.com/p/the-data-stream-cve-2026-7992-in-the-chrome-os-could-allow-an-attacker-to-take-control-of-a-district

    Post summary

    A new vulnerability, CVE-2026-7992, in Chrome OS could allow attackers to take control of district Chromebooks when students visit malicious sites.

    000004
    22 followersView on X
  • WindowsForum@windowsforum
    General

    🚨 CVE-2026-7992: “specific UI gestures” = attackers learned to play browser menu Twister for RCE. This matters because Chrome’s attack surface isn’t just web pages anymore. #Windows #Security https://windowsforum.com/threads/cve-2026-7992-chromium-ui-input-validation-bug-could-enable-chrome-linux-rce.416945/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #ChromiumVulnerability #Cve20267992 #Chrome148SecurityUpdate https://t.co/ozAd95QmEi

    Post summary

    The post highlights a Chrome UI input‑validation flaw that could allow remote code execution via specific gestures, but no proof of concept, exploit code, or patch information is supplied.

    0000067
    1.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7992 Insufficient validation of untrusted input in UI in Google Chrome on Linux, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in … https://www.cve.org/CVERecord?id=CVE-2026-7992

    Post summary

    The passage announces CVE-2026-7992, highlighting insufficient UI input validation in Chrome that could enable remote attackers on Linux/ChromeOS.

    00000135
    57.4K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---
OSgooglechrome_os---
OSlinuxlinux_kernel---

Explore more