PatchSiren cyber security CVE debrief
CVE-2026-8546 Google CVE debrief
CVE-2026-8546 is an out-of-bounds read vulnerability in the GPU component of Google Chrome affecting macOS and Windows platforms. The flaw, rated High severity by Chromium with a CVSS 3.1 score of 5.3 (Medium), was published on 2026-05-14 and last modified on 2026-05-19. The vulnerability allows a remote attacker who has already compromised the renderer process to obtain potentially sensitive information from process memory by convincing a user to visit a crafted HTML page. The attack requires user interaction and has high attack complexity, with no impact to integrity or availability. Google addressed this issue in Chrome version 148.0.7778.168. The underlying weakness is CWE-125 (Out-of-bounds Read). No known exploitation in the wild has been reported, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.
- Vendor
- Product
- Chrome
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-14
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-14
- Advisory updated
- 2026-05-19
Who should care
Organizations and individuals running Google Chrome on macOS or Windows systems, particularly those handling sensitive data in browser sessions. Security teams responsible for browser security posture and patch management. Enterprises with bring-your-own-device policies where Chrome versions may vary across endpoints.
Technical summary
The vulnerability exists in Chrome's GPU processing implementation where insufficient bounds checking allows memory to be read beyond allocated buffers. An attacker with renderer process compromise can leverage this to extract sensitive data from process memory. The attack vector is network-based with required user interaction (visiting malicious page) and high attack complexity. The CVSS vector CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N reflects these characteristics: network attack vector, high complexity, no privileges required, user interaction needed, unchanged scope, high confidentiality impact, no integrity or availability impact.
Defensive priority
medium
Recommended defensive actions
- Update Google Chrome to version 148.0.7778.168 or later on macOS and Windows systems.
- Verify Chrome version via chrome://settings/help and apply pending updates immediately.
- Consider enabling automatic updates for Chrome to ensure timely patch application.
- Monitor for unusual renderer process behavior or unexpected memory access patterns in browser environments.
- Review and restrict execution of untrusted HTML content in sandboxed environments where possible.
Evidence notes
Vulnerability description and CVSS scoring derived from NVD record and Chromium security advisory. Affected product versions and patch information confirmed via Chrome Release Blog. CPE data indicates vulnerability affects Google Chrome prior to 148.0.7778.168 on macOS and Windows platforms.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8546 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8546
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8546 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8546
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_12.html
[email protected] - Product, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://issues.chromium.org/issues/497531791
[email protected] - Permissions Required
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.