CVE-2026-8509
CVSS 8.8 HIGH: heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. Microsoft patch: Release Notes.
Vulnerabilities · 123 days ago
Chrome 148 is not a single-fix patch. It closes a wide set of critical memory-safety bugs across Chromium subsystems, and most of the critical issues were found by Google itself, which points to ongoing weakness in the browser’s shared attack surface.
The update resolves 79 vulnerabilities, including 14 critical issues. The highlighted flaws are CVE-2026-8509, a heap buffer overflow in WebML, and CVE-2026-8510, an integer overflow in Skia. The rest of the critical bugs span UI, FileSystem, Input, Aura, HID, Blink, Tab Groups, Downloads, DataTransfer, WebShare, ANGLE, and Payments. Google also released Firefox 150.0.3 with five high-severity fixes.
For defenders, the takeaway is that Chrome’s risk here is systemic. Patch cadence matters, but so does expecting more memory-safety bugs to keep surfacing in different Chromium components.
CVSS 8.8 HIGH: heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. Microsoft patch: Release Notes.
CVSS 7.5 HIGH: integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had… Microsoft patch: Release Notes.
1 source covering this story
Chrome 148 Update Patches Critical Vulnerabilities
The refresh resolves critical-severity use-after-free and other types of bugs in various browser components.
Part of the PlainSec briefing for 2026-05-16