Junglewise Threat Intelligence

CVE-2026-8545: Google Chrome object corruption in Compositing

CVE-2026-8545 · Severity: low · CVSS 3.1 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its compositing engine—the component responsible for drawing web page elements—could allow a malicious website to access sensitive data from other websites you have open. This could lead to the exposure of private information, though an attacker would first need to have already compromised a specific part of the browser's internal processes.

Technical details

An object corruption vulnerability exists in the Compositing component of Google Chrome. The flaw is reachable via a crafted HTML page and requires the attacker to have already achieved code execution within a compromised renderer process (a 'sandbox escape' or similar initial compromise is a prerequisite). If successful, the attacker can bypass cross-origin isolation boundaries to leak sensitive data from other origins. Google has addressed this in version 148.0.7778.168. While the provided CVSS score is 3.1 (Low), Chromium's internal severity rating is High due to the potential for cross-origin data exfiltration.

Affected products

  • Google Chrome Prior to 148.0.7778.168

Timeline

  • 2026-03-29: disclosed: Reported to Chromium by Google researchers
  • 2026-05-12: patched: Fixed in Chrome Stable channel update 148.0.7778.168
  • 2026-05-14: advisory: NVD publication date

References

Related threats