PatchSiren cyber security CVE debrief
CVE-2026-8562 Apple CVE debrief
CVE-2026-8562 is a medium-severity information disclosure issue in Google Chrome's Navigation component. A remote attacker can use a crafted HTML page to trigger a side-channel leak of cross-origin data in versions before 148.0.7778.168. The record is rated CVSS 4.3 and requires user interaction.
- Vendor
- Apple
- Product
- Unknown
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-14
- Original CVE updated
- 2026-05-18
- Advisory published
- 2026-05-14
- Advisory updated
- 2026-05-18
Who should care
Organizations and individuals running Google Chrome versions earlier than 148.0.7778.168 should care, especially managed desktop fleets and users who routinely browse untrusted content. Security teams responsible for browser patching and update compliance should prioritize validation of the fixed release.
Technical summary
NVD describes this as a side-channel information leakage flaw in Navigation in Google Chrome prior to 148.0.7778.168. The attacker model is remote, and the attack is delivered through a crafted HTML page that can leak cross-origin data. The CVSS vector is AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N, and the associated weakness is CWE-1300.
Defensive priority
Medium. The issue can expose limited confidentiality data and does require user interaction, but it affects a widely deployed browser and is remediated by updating to the fixed Chrome release.
Recommended defensive actions
- Update Google Chrome to version 148.0.7778.168 or later.
- Verify that managed endpoints are receiving and applying the browser update.
- Prioritize patching on systems that regularly access untrusted or externally supplied web content.
- Confirm browser version compliance in enterprise asset and endpoint management tools.
Evidence notes
The supplied NVD record marks Google Chrome as vulnerable only up to version 148.0.7778.168 and cites the Chromium stable channel update plus Chromium issue 40057534. The record's CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N, with CWE-1300 listed as the weakness. The supplied vendor metadata is inconsistent: the vendor field says Apple, but the vulnerability references and affected CPE clearly point to Google Chrome. Apple/macOS/Linux/Windows CPE entries in the record are marked not vulnerable.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8562 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8562
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8562 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8562
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_12.html
[email protected] - Product, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://issues.chromium.org/issues/40057534
[email protected] - Permissions Required
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.