CVE•Published 2026-05-06•Modified 2026-05-08•1 article on news•5 live references•NVD data
CVE-2026-8018Google · Chrome
Vulnerability data via NVD (ingested)
CVSS v3.1
8.1
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS percentile
—
Weaknesses (CWE)
Description
Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Low)
Timeline
Published 2026-05-06
Modified 2026-05-08
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag0 hosts
vuln:CVE-2026-8018Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · product
product:"Google Chrome"All exposed Google Chrome instances — cross-reference with the CVE's affected-version range.
Shodan · banner/body mention
http.html:"Chrome"HTTP body or banner mentions "Chrome" — catches deploys Shodan didn't identify as a product.
More intel sources (5)
Shodan report
vuln:CVE-2026-8018Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-8018Censys host search filtered to this CVE id.
grep.app
CVE-2026-8018Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-8018GitHub code search for direct mentions.
Google dork
"CVE-2026-8018" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (8)
CVE-2026-80188 repos
tycloud97/awesome-starsunknown
A curated list of my GitHub stars by stargazed
robertsdotpm/tiddlyinstallHTML
A single HTML file that makes installers for your open source projects.
dick318/awesome-starsunknown
automotive-security/Automotive-Security-GlossaryJavaScript
A glossary of automotive cybersecurity terminology that provides clear and concise definitions of automotive security concepts.
Supermagnum/Galdralag-firmwareRust
A cryptographic framework for Baochip-1x .
dolphlabs/slangC
A statically typed language for server-side and network programming. spawn is M:N — green tasks on a worker pool, not a thread per connection. Accept, recv, and send park. Memory i…
blamejs/pkiJavaScript
Pure-JavaScript PKI toolkit that owns its stack — X.509, ASN.1/DER, CMS, PQC-first.
md6ba/sec_standardsHTML
Security Standards Knowledge Base — authoritative collection of NIST, IETF, OWASP, and other security standards for building security-sensitive software.