You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2026-7975
About this tag
CVE-2026-7975 is a Chromium use-after-free vulnerability in DevTools, disclosed by Google and Microsoft on May 6, 2026. The flaw was fixed in Google Chrome before version 148.0.7778.96 and also affects Chromium-based Microsoft Edge. While Chromium rates it as Medium severity, CISA's ADP scoring assigns an 8.3 High CVSS 3.1 score because the bug could help an attacker escape Chrome's sandbox after a renderer compromise. This highlights the importance of fast patching, as attackers chain multiple bugs together to achieve full compromise. WindowsForum discussions emphasize that even medium-rated browser bugs need prompt attention to prevent sandbox escapes and maintain security.
Google and Microsoft disclosed CVE-2026-7975 on May 6, 2026, a Chromium use-after-free flaw in DevTools fixed in Google Chrome before version 148.0.7778.96 and tracked by MSRC for Chromium-based Edge because the shared browser engine carries the same security debt. The bug is rated “Medium” by...