Junglewise Threat Intelligence

CVE-2026-8546: Google Chrome out of bounds read in GPU

CVE-2026-8546 · Severity: medium · CVSS 5.3 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its graphics processing component could allow a remote attacker to access sensitive information from the browser's memory. This requires the attacker to first compromise a website's rendering process and then trick a user into visiting a specially crafted web page.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the GPU component of Google Chrome for Mac and Windows prior to version 148.0.7778.168. The flaw is reachable by a remote attacker who has already compromised the renderer process. By convincing a user to load a specially crafted HTML page, the attacker can exploit this memory safety issue to read sensitive information from the process memory. This vulnerability was reported by Google internally and is addressed in the Stable Channel update 148.0.7778.167/168.

Affected products

  • Google Chrome Prior to 148.0.7778.168

Timeline

  • 2026-03-29: disclosed: Reported to Chromium project
  • 2026-05-12: patched: Fixed in Stable Channel Update for Desktop
  • 2026-05-14: advisory: NVD publication date

References

Related threats