PatchSiren cyber security CVE debrief
CVE-2026-8584 Google CVE debrief
A UI spoofing vulnerability in Google Chrome on iOS, rated Medium severity (CVSS 4.2), was addressed in version 148.0.7778.168. The flaw stemmed from inappropriate implementation in Views, allowing a remote attacker who had already compromised the renderer process to spoof UI elements via a crafted HTML page. The attack requires high complexity and user interaction, with limited confidentiality and availability impact. No evidence of active exploitation or ransomware campaign use has been identified.
- Vendor
- Product
- Chrome
- CVSS
- MEDIUM 4.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-14
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-14
- Advisory updated
- 2026-05-19
Who should care
Organizations with iOS device fleets using Google Chrome; security teams monitoring browser security posture; mobile application security practitioners; incident responders investigating potential browser-based social engineering campaigns.
Technical summary
The vulnerability exists in the Views implementation of Google Chrome on iOS. An attacker who has already achieved renderer process compromise can leverage this flaw to perform UI spoofing through a crafted HTML page. The CVSS 3.1 vector (AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L) reflects network attack vector, high attack complexity, no privileges required, user interaction required, unchanged scope, with low confidentiality impact, no integrity impact, and low availability impact. The fix was released in Chrome iOS version 148.0.7778.168.
Defensive priority
medium
Recommended defensive actions
- Update Google Chrome on iOS devices to version 148.0.7778.168 or later
- Monitor for unexpected UI behavior in Chrome on iOS that may indicate renderer compromise
- Apply standard browser security hygiene including avoiding untrusted sites and suspicious links
- Review Chromium security advisories for additional context on renderer process hardening
Evidence notes
CVE published 2026-05-14; modified 2026-05-19. Vendor advisory confirms fix in Chrome iOS 148.0.7778.168. Chromium issue tracker reference requires permissions to access full details. CPE data indicates vulnerability affects Google Chrome on iOS; Apple iPhone OS listed as non-vulnerable platform context.
Official resources
-
CVE-2026-8584 CVE record
CVE.org
-
CVE-2026-8584 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
-
Source reference
[email protected] - Permissions Required
2026-05-14