Remote Code Execution Vulnerability in Google Chrome
CVE-2026-7989

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
6 May 2026

What is CVE-2026-7989?

A vulnerability has been identified in Google Chrome which relates to insufficient data validation in the DataTransfer component. This flaw permits a remote attacker, who has successfully compromised the renderer process, to execute arbitrary read and write operations. By leveraging a specially crafted HTML page, attackers could exploit this vulnerability to manipulate data undetected. Users are advised to update their Chrome browser to the latest version to mitigate this risk.

Affected Version(s)

Chrome 148.0.7778.96

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.