2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8548 — Out: of bounds write in Media in Google Chrome prior to 148.0.7778.168 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8548

Out of bounds write in Media in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 787TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8544 — Use: after free in Media in Google Chrome prior to 148.0.7778.168 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8544

Use after free in Media in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8542 — Use: after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8542

Use after free in Core in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8540 — Type: Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8540

Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8534 — Integer: overflow in GPU in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8534

Integer overflow in GPU in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 472TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8533 — Use: after free in Accessibility in Google Chrome prior to 148.0.7778.168 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8533

Use after free in Accessibility in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8532 — Integer: overflow in XML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8532

Integer overflow in XML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 472TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8531 — Heap: buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8531

Heap buffer overflow in WebML in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8530 — Use: after free in Network in Google Chrome on Windows prior to 148.0.7778.168 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8530

Use after free in Network in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8529 — Heap: buffer overflow in Codecs in Google Chrome prior to 148.0.7778.168 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8529

Heap buffer overflow in Codecs in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8527 — Insufficient validation of untrusted input in Downloads in Google Chrome prior to 148.0.7778.168 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8527

Insufficient validation of untrusted input in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 20TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8526 — Out: of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8526

Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8525 — Heap: buffer overflow in ANGLE in Google Chrome on Mac prior to 148.0.7778.168 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8525

Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8524 — Out: of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8524

Out of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8523 — Use: after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8523

Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8522 — Use: after free in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8522

Use after free in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8520 — Race: in Payments in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8520

Race in Payments in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 362VNDRaceTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8519 — Integer: overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8519

Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 472TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8518 — Use: after free in Blink in Google Chrome prior to 148.0.7778.168 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8518

Use after free in Blink in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8517 — Object: lifecycle issue in WebShare in Google Chrome on Mac prior to 148.0.7778.168 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8517

Object lifecycle issue in WebShare in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.8 (HIGH)

CWECWE 664VNDObjectTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8515 — Use: after free in HID in Google Chrome prior to 148.0.7778.168 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8515

Use after free in HID in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8514 — Use: after free in Aura in Google Chrome prior to 148.0.7778.168 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8514

Use after free in Aura in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8513 — Use: after free in Input in Google Chrome on Android prior to 148.0.7778.168 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8513

Use after free in Input in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
HIGH

CVE-2026-8512 — Use: after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8512

Use after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-14
2026-05-14 20:17Z
CRIT

CVE-2026-8511 — Use: after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8511

Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score