CVE-2026-8509
CVSS 8.8 HIGH: heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. Patch Microsoft: Release Notes.
Vulnerabilità · 138 giorni fa
Chrome 148 non è una patch con una sola correzione. Chiude un ampio insieme di bug critici di memory-safety in diversi sottosistemi di Chromium, e la maggior parte dei problemi critici è stata trovata da Google stessa, il che indica una debolezza persistente nella superficie d’attacco condivisa del browser.
CVSS 8.8 HIGH: heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. Patch Microsoft: Release Notes.
CVSS 7.5 HIGH: integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had… Patch Microsoft: Release Notes.
1 fonte che coprono questa storia
Chrome 148 Update Patches Critical Vulnerabilities
The refresh resolves critical-severity use-after-free and other types of bugs in various browser components.
Part of the PlainSec briefing for 2026-05-16