PT-2026-38185 · Google · Google Chrome

Published

2026-05-06

·

Updated

2026-05-22

·

CVE-2026-7992

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome on Linux versions prior to 148.0.7778.96 Google Chrome on ChromeOS versions prior to 148.0.7778.96
Description Insufficient validation of untrusted input in the UI allows a remote attacker to execute arbitrary code via a crafted HTML page, provided they can convince a user to perform specific UI gestures.
Recommendations Update Google Chrome on Linux to version 148.0.7778.96 or later. Update Google Chrome on ChromeOS to version 148.0.7778.96 or later.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-7992
ECHO-2EDD-E9A0-E215
OPENSUSE-SU-2026:10778-1

Affected Products

Google Chrome