Junglewise Threat Intelligence

CVE-2026-8517: Google Chrome WebShare object lifecycle issue on Mac

CVE-2026-8517 · Severity: high · CVSS 8.8 · Published 2026-05-14

Technologies: Apple macOS, Google Chrome. Vendors: Apple, Google.

Executive brief

A critical vulnerability exists in the WebShare component of Google Chrome for Mac. This component allows websites to share text, links, and other content to other apps on the user's device. If a user is tricked into visiting a malicious website and performing specific interactions, an attacker could execute unauthorized code on the user's computer, potentially leading to full system compromise or data theft.

Technical details

An object lifecycle issue (likely a use-after-free or similar memory management error) exists in the WebShare implementation of Google Chrome on macOS. The vulnerability is triggered when a remote attacker convinces a user to visit a specially crafted HTML page and perform specific UI gestures. Successful exploitation allows the attacker to achieve arbitrary code execution within the context of the browser process. Google has addressed this in version 148.0.7778.168 for Mac. While the reported CVSS is 8.8 (High), Chromium's internal severity rating for this specific issue is 'Critical'.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-03-29: disclosed: Reported by Google internal researchers
  • 2026-05-12: patched: Fixed in Chrome Stable Channel update 148.0.7778.168
  • 2026-05-14: advisory: NVD publication date

References

Related threats