Junglewise Threat Intelligence

CVE-2026-8509: Google Chrome heap buffer overflow in WebML

CVE-2026-8509 · Severity: high · CVSS 8.8 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical vulnerability exists in Google Chrome's WebML component, which handles machine learning capabilities within the browser. By tricking a user into visiting a specially crafted website, an attacker could execute malicious code on the user's computer. While this code is restricted by the browser's security sandbox, it could still lead to data theft or be used as a stepping stone for further attacks on the system.

Technical details

A heap-based buffer overflow (CWE-122) exists in the WebML component of Google Chrome. The vulnerability is triggered when the browser processes a specially crafted HTML page, allowing a remote, unauthenticated attacker to overflow memory and potentially execute arbitrary code. While the execution is confined within the Chromium sandbox, it represents a significant security risk. The issue was addressed in Chrome version 148.0.7778.168 for Desktop. The vulnerability was reported by an external researcher and assigned a critical severity rating by the Chromium team.

Affected products

  • Google Chrome Prior to 148.0.7778.168

Timeline

  • 2026-03-17: other: Vulnerability reported to Chrome team
  • 2026-05-12: patched: Stable channel update released for Windows, Mac, and Linux
  • 2026-05-14: disclosed: CVE published to NVD

References

Related threats