CVE-2026-7948
High
Published: 06 May 2026
Published
06 May 2026
Modified
07 May 2026
KEV Added
—
Patch
—
CVSS Score
7.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
N/A
Risk Priority
15
60% EPSS · 20% KEV · 20% CVSS
Description
Race in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)
Likely Mitigating ControlsAI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
addresses: CWE-362
Accurate timestamps from internal clocks enable detection of race conditions by providing reliable event ordering in audit logs.
addresses: CWE-362
Coordination of concurrent security activities reduces the probability that shared resources will be accessed simultaneously without proper synchronization.
Security SummaryAI
Automated synthesis unavailable for this CVE.
Details
- CWE(s)
Affected Products
google
chrome
≤ 148.0.7778.96