Junglewise Threat Intelligence

CVE-2026-8516: Google Chrome improper input validation in DataTransfer

CVE-2026-8516 · Severity: medium · CVSS 5.3 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the browser's data transfer component could allow a malicious website to access sensitive information from the computer's memory. To succeed, an attacker must trick a user into performing specific mouse or keyboard actions on a specially crafted webpage.

Technical details

An improper input validation vulnerability (CWE-20) exists in the DataTransfer component of Google Chrome. A remote attacker can exploit this by hosting a malicious HTML page and convincing a user to perform specific UI gestures (such as drag-and-drop or clipboard actions). Successful exploitation allows the attacker to read sensitive information from the browser's process memory. While the reported CVSS score is 5.3 (Medium), Chromium has assigned this a 'Critical' security severity. The issue is resolved in version 148.0.7778.168 and later.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-03-26: other: Reported by Google internal researchers
  • 2026-05-12: patched: Fixed in version 148.0.7778.168
  • 2026-05-14: disclosed: Public advisory published

References

Related threats