Junglewise Threat Intelligence

CVE-2026-8547: Google Chrome insufficient policy enforcement in Passwords

CVE-2026-8547 · Severity: high · CVSS 7.5 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's password management component on Windows could allow an attacker to gain elevated privileges on a user's system. To exploit this, an attacker would first need to compromise the browser's content-rendering process and then trick a user into visiting a specially crafted webpage. This could lead to unauthorized access to sensitive information or the ability to perform actions with higher-level system permissions.

Technical details

An insufficient policy enforcement vulnerability exists in the Passwords component of Google Chrome on Windows. The flaw allows a remote attacker who has already achieved code execution within the sandboxed renderer process to bypass security boundaries and escalate privileges. This is achieved by enticing a user to load a specially crafted HTML page. The vulnerability is addressed in Chrome version 148.0.7778.168 for Windows.

Affected products

  • Google Chrome Prior to 148.0.7778.168

Timeline

  • 2026-03-30: disclosed: Reported to Chrome by Google internal researchers
  • 2026-05-12: patched: Stable channel update released for Windows
  • 2026-05-14: advisory: NVD publication date

References

Related threats