CVE-2026-7904: Out of bounds read in Fonts
Chromium: CVE-2026-7904 Out of bounds read in Fonts
Other sources
Out of bounds read in Fonts in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 148.0.7778.96 - Upgrade
Upgrade
Google Chrome/Chromium (fonts)to a version that resolves this vulnerability.Fixed in 148.0.7778.96
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-7896
- CVE-2026-7897
- CVE-2026-7898
- CVE-2026-7899
- CVE-2026-7900
- CVE-2026-7901
- CVE-2026-7902
- CVE-2026-7903
- CVE-2026-7905
- CVE-2026-7906
- CVE-2026-7907
- CVE-2026-7908
- CVE-2026-7909
- CVE-2026-7910
- CVE-2026-7911
- CVE-2026-7912
- CVE-2026-7913
- CVE-2026-7914
- CVE-2026-7915
- CVE-2026-7916
- CVE-2026-7917
- CVE-2026-7918
- CVE-2026-7919
- CVE-2026-7920
- CVE-2026-7921
- CVE-2026-7922
- CVE-2026-7923
- CVE-2026-7924
- CVE-2026-7925
- CVE-2026-7926
- CVE-2026-7927
- CVE-2026-7928
- CVE-2026-7929
- CVE-2026-7931
- CVE-2026-7932
- CVE-2026-7933
- CVE-2026-7934
- CVE-2026-7935
- CVE-2026-7937
- CVE-2026-7938
- CVE-2026-7939
- CVE-2026-7940
- CVE-2026-7941
- CVE-2026-7942
- CVE-2026-7943
- CVE-2026-7944
- CVE-2026-7945
- CVE-2026-7946
- CVE-2026-7947
- CVE-2026-7948
- CVE-2026-7949
- CVE-2026-7950
- CVE-2026-7951
- CVE-2026-7952
- CVE-2026-7953
- CVE-2026-7954
- CVE-2026-7955
- CVE-2026-7956
- CVE-2026-7957
- CVE-2026-7958
- CVE-2026-7959
- CVE-2026-7960
- CVE-2026-7961
- CVE-2026-7962
- CVE-2026-7963
- CVE-2026-7964
- CVE-2026-7965
- CVE-2026-7966
- CVE-2026-7967
- CVE-2026-7968
- CVE-2026-7969
- CVE-2026-7970
- CVE-2026-7971
- CVE-2026-7972
- CVE-2026-7973
- CVE-2026-7974
- CVE-2026-7975
- CVE-2026-7976
- CVE-2026-7977
- CVE-2026-7978
- CVE-2026-7979
- CVE-2026-7980
- CVE-2026-7981
- CVE-2026-7982
- CVE-2026-7983
- CVE-2026-7984
- CVE-2026-7985
- CVE-2026-7986
- CVE-2026-7987
- CVE-2026-7988
- CVE-2026-7989
- CVE-2026-7990
- CVE-2026-7991
- CVE-2026-7992
- CVE-2026-7993
- CVE-2026-7994
- CVE-2026-7995
- CVE-2026-7996
- CVE-2026-7997
- CVE-2026-7998
- CVE-2026-7999
- CVE-2026-8000
- CVE-2026-8001
- CVE-2026-8002
- CVE-2026-8003
- CVE-2026-8004
- CVE-2026-8005
- CVE-2026-8006
- CVE-2026-8007
- CVE-2026-8008
- CVE-2026-8009
- CVE-2026-8010
- CVE-2026-8011
- CVE-2026-8012
- CVE-2026-8013
- CVE-2026-8014
- CVE-2026-8015
- CVE-2026-8016
- CVE-2026-8017
- CVE-2026-8018
- CVE-2026-8019
- CVE-2026-8020
- CVE-2026-8021
- CVE-2026-8022
Frequently Asked Questions
What is the severity of CVE-2026-7904?
CVE-2026-7904 has a medium severity rating of 4.3 according to the CVSS 3.1 scoring methodology.
How do I fix CVE-2026-7904?
To fix CVE-2026-7904, update Google Chrome and Microsoft Edge to version 148.0.7778.96 or later.
What type of vulnerability is CVE-2026-7904?
CVE-2026-7904 is an out of bounds read vulnerability that affects the Fonts component in Google Chrome.
Which software versions are impacted by CVE-2026-7904?
CVE-2026-7904 impacts Google Chrome versions prior to 148.0.7778.96 and some versions of Microsoft Edge.
What could an attacker do with CVE-2026-7904?
An attacker could exploit CVE-2026-7904 to perform an out of bounds memory read via a specially crafted HTML page.