PatchSiren cyber security CVE debrief
CVE-2026-8543 Google CVE debrief
CVE-2026-8543 is an out-of-bounds read vulnerability in the FileSystem component of Google Chrome on macOS. The flaw, rated High severity by Chromium security with a CVSS 3.1 score of 5.3 (Medium), was present in versions prior to 148.0.7778.168. A remote attacker could exploit this vulnerability by convincing a user to perform specific UI gestures, potentially allowing extraction of sensitive information from process memory via a crafted HTML page. The vulnerability was published on May 14, 2026, with the NVD record last modified on May 19, 2026. The root cause is categorized as CWE-125 (Out-of-bounds Read).
- Vendor
- Product
- Chrome
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-14
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-14
- Advisory updated
- 2026-05-19
Who should care
Organizations with macOS endpoints running Google Chrome, security teams managing browser security configurations, and users who rely on Chrome for sensitive web activities should prioritize this update. The vulnerability is particularly relevant for environments where users may be targeted with social engineering to perform specific UI gestures.
Technical summary
This vulnerability exists in the FileSystem implementation within Google Chrome for macOS. The out-of-bounds read condition can be triggered when processing specially crafted HTML content combined with specific user interface interactions. Successful exploitation could result in disclosure of sensitive information from browser process memory. The attack requires user interaction and has high attack complexity, limiting its practical exploitability. The fix was released in Chrome stable channel version 148.0.7778.168.
Defensive priority
medium
Recommended defensive actions
- Update Google Chrome to version 148.0.7778.168 or later on macOS systems.
- Review and apply the stable channel update referenced in the Chrome release notes.
- Monitor for additional Chromium security advisories related to FileSystem component fixes.
- Consider implementing application control policies to restrict browser execution to approved versions.
- Educate users on the risks of engaging with untrusted web content that may require specific UI interactions.
Evidence notes
The vulnerability affects Google Chrome on macOS specifically, with the CPE configuration indicating Chrome versions below 148.0.7778.168 are vulnerable. The macOS operating system itself is marked as not vulnerable in the CPE data. The CVSS vector (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N) indicates network attack vector, high attack complexity, no privileges required, user interaction required, unchanged scope, high confidentiality impact, and no integrity or availability impact.
Official resources
-
CVE-2026-8543 CVE record
CVE.org
-
CVE-2026-8543 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Product, Vendor Advisory
-
Source reference
[email protected] - Permissions Required
The vulnerability was disclosed through official Chromium security channels on May 14, 2026, with an update to the NVD record on May 19, 2026. No known exploitation in the wild has been reported, and the vulnerability is not listed in CISAĆ¢