Vulnerability intelligence
CVE-2026-7896
Integer overflow in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CVSS Score
8.8
High
EPSS — Exploit Probability
0.3%
Riskier than 20% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered May 7, 2026 · latest May 7, 2026
Coverage timeline
-
Chrome 148 Update Fixes 127 Flaws, Including Three Critical Bugswww.securityweek.com · May 7, 2026