PatchSiren cyber security CVE debrief
CVE-2026-8571 Google CVE debrief
A sandbox escape vulnerability in Google Chrome on Android, stemming from insufficient policy enforcement in the GPU component. A remote attacker who has already compromised the renderer process could leverage this flaw to escape the browser sandbox via a crafted HTML page. The vulnerability affects Chrome versions prior to 148.0.7778.168 on Android. Google has assigned this a Medium severity rating, while NVD's CVSS 3.1 scoring reflects a HIGH severity (8.3) due to the potential for complete confidentiality, integrity, and availability impact within the changed scope. The issue was addressed in the May 2026 stable channel update.
- Vendor
- Product
- Chrome
- CVSS
- HIGH 8.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-14
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-14
- Advisory updated
- 2026-05-19
Who should care
Organizations with Android device fleets using Chrome for business browsing; mobile security teams; BYOD environments; users handling sensitive data on Android Chrome browsers
Technical summary
The vulnerability exists in Chrome's GPU process policy enforcement on Android. An attacker with renderer process compromise can craft malicious HTML to bypass sandbox restrictions. The fix was released in Chrome 148.0.7778.168. CVSS 3.1 vector: AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H. CWE-693 (Protection Mechanism Failure) identified as weakness type.
Defensive priority
high
Recommended defensive actions
- Update Google Chrome on Android devices to version 148.0.7778.168 or later
- Prioritize patching for devices where users browse untrusted web content
- Monitor for signs of renderer process compromise as potential precursor to exploitation
- Review application sandboxing controls for mobile browser deployments
- Consider implementing site isolation policies to limit renderer compromise impact
Evidence notes
CVE published 2026-05-14; modified 2026-05-19. Vendor advisory confirms fix in Chrome 148.0.7778.168. Chromium issue tracker reference requires permissions to view full details. CPE indicates vulnerability affects Chrome on Android specifically.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8571 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8571
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8571 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8571
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_12.html
[email protected] - Vendor Advisory, Release Notes
-
Source reference
Unverified legacy reference
URL: https://issues.chromium.org/issues/491422244
[email protected] - Permissions Required
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.