Subscribe, build a custom feed, or pitch a sponsorship at hello@acadenix.com
Latest intel// live feed
CVE-2026-8574 — Use: after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed
Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)
CVE-2026-8573 — Integer: overflow in Codecs in Google Chrome on Windows prior to 148.0.7778.168 allowed a
Integer overflow in Codecs in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)
CVE-2026-8571 — GPU: Insufficient policy enforcement in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed
Insufficient policy enforcement in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)
CVE-2026-8569 — Out: of bounds write in Codecs in Google Chrome on Mac prior to 148.0.7778.168
Out of bounds write in Codecs in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium) CVSSv3.1 8.3 (HIGH)
CVE-2026-8558 — Out: of bounds write in Fonts in Google Chrome prior to 148.0.7778.168 allowed a
Out of bounds write in Fonts in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)
CVE-2026-8555 — Use: after free in GTK in Google Chrome on Windows prior to 148.0.7778.168 allowed
Use after free in GTK in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)
CVE-2026-8551 — Use: after free in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote
Use after free in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)
CVE-2026-8549 — Use: after free in Media in Google Chrome prior to 148.0.7778.168 allowed a remote
Use after free in Media in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)
CVE-2026-8548 — Out: of bounds write in Media in Google Chrome prior to 148.0.7778.168 allowed a
Out of bounds write in Media in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)
CVE-2026-8544 — Use: after free in Media in Google Chrome prior to 148.0.7778.168 allowed a remote
Use after free in Media in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)
CVE-2026-8542 — Use: after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed
Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)
CVE-2026-8540 — Type: Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker
Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)
CVE-2026-8534 — Integer: overflow in GPU in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168
Integer overflow in GPU in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)
CVE-2026-8533 — Use: after free in Accessibility in Google Chrome prior to 148.0.7778.168 allowed a remote
Use after free in Accessibility in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)
CVE-2026-8532 — Integer: overflow in XML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker
Integer overflow in XML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)
CVE-2026-8531 — Heap: buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed
Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)
CVE-2026-8530 — Use: after free in Network in Google Chrome on Windows prior to 148.0.7778.168 allowed
Use after free in Network in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)
CVE-2026-8529 — Heap: buffer overflow in Codecs in Google Chrome prior to 148.0.7778.168 allowed a remote
Heap buffer overflow in Codecs in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)
CVE-2026-8527 — Insufficient validation of untrusted input in Downloads in Google Chrome prior to 148.0.7778.168 allowed
Insufficient validation of untrusted input in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)
CVE-2026-8526 — Out: of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a
Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)
CVE-2026-8525 — Heap: buffer overflow in ANGLE in Google Chrome on Mac prior to 148.0.7778.168 allowed
Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)
CVE-2026-8524 — Out: of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a
Out of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)
CVE-2026-8523 — Use: after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote
Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)
CVE-2026-8522 — Use: after free in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed
Use after free in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)
CVE-2026-8520 — Race: in Payments in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to
Race in Payments in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)