Junglewise Threat Intelligence

CVE-2026-8529: Google Chrome heap buffer overflow in Codecs

CVE-2026-8529 · Severity: high · CVSS 8.8 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser for accessing the internet and running web applications. A security vulnerability in the browser's video processing components could allow an attacker to execute malicious code on a user's computer if they are tricked into opening a specially crafted video file. While the browser's built-in security 'sandbox' provides some protection, this flaw could lead to unauthorized access to data or system instability within that restricted environment.

Technical details

A heap-based buffer overflow (CWE-122) exists in the Codecs component of Google Chrome. The vulnerability is triggered when the browser processes a specially crafted video file, leading to memory corruption. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website or open a malicious video file. Successful exploitation allows for arbitrary code execution within the context of the Chrome sandbox. This issue was resolved in version 148.0.7778.168 for Mac and Windows, and 148.0.7778.167 for Linux.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-03-06: other: Reported by Google researchers
  • 2026-05-12: patched: Fixed in version 148.0.7778.168/167
  • 2026-05-14: disclosed: NVD publication date

References

Related threats