Vulnerabilities & Exploits

Chrome 148 Cuts Across Chromium’s Memory-Safety Surface

Chrome 148 is not a single-fix patch. It closes a wide set of critical memory-safety bugs across Chromium subsystems, and most of the critical issues were found by Google itself, which points to ongoing weakness in the browser’s shared attack surface.

The update resolves 79 vulnerabilities, including 14 critical issues. The highlighted flaws are CVE-2026-8509, a heap buffer overflow in WebML, and CVE-2026-8510, an integer overflow in Skia. The rest of the critical bugs span UI, FileSystem, Input, Aura, HID, Blink, Tab Groups, Downloads, DataTransfer, WebShare, ANGLE, and Payments. Google also released Firefox 150.0.3 with five high-severity fixes.

For defenders, the takeaway is that Chrome’s risk here is systemic. Patch cadence matters, but so does expecting more memory-safety bugs to keep surfacing in different Chromium components.

1 source · May 15

CVE-2026-8509

NVD KEV

CVSS 8.8 HIGH: heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. Microsoft patch: Release Notes.

CVE-2026-8510

NVD KEV

CVSS 7.5 HIGH: integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had… Microsoft patch: Release Notes.

Timeline

Sources

Part of the PlainSec briefing for 2026-05-15

Every edition of this story: Chrome 148 Cuts Across Chromium’s Memory-Safety Surface

More from today