CVE-2026-8509
CVSS 8.8 HIGH: heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. Patch Microsoft: Release Notes.
Vulnerabilità ed exploit
Chrome 148 non è una patch con una sola correzione. Chiude un ampio insieme di bug critici di memory-safety in diversi sottosistemi di Chromium, e la maggior parte dei problemi critici è stata trovata da Google stessa, il che indica una debolezza persistente nella superficie d’attacco condivisa del browser.
1 fonte · 15 mag
CVSS 8.8 HIGH: heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. Patch Microsoft: Release Notes.
CVSS 7.5 HIGH: integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had… Patch Microsoft: Release Notes.
SecurityWeek
Chrome 148 Update Patches Critical Vulnerabilities
The refresh resolves critical-severity use-after-free and other types of bugs in various browser components.
originalePart of the PlainSec briefing for 2026-05-15
Every edition of this story: Chrome 148 taglia trasversalmente la superficie di memory-safety di Chromium