Junglewise Threat Intelligence

CVE-2026-8548: Google Chrome out of bounds write in Media

CVE-2026-8548 · Severity: high · CVSS 8.3 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its media processing component could allow a remote attacker to bypass security protections (the sandbox) that normally isolate the browser from the rest of the computer. If exploited, this could allow an attacker to gain unauthorized access to the underlying operating system and user data after a user visits a malicious website.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the Media component of Google Chrome prior to version 148.0.7778.168. The flaw is reachable via a crafted HTML page and requires the attacker to have already compromised the renderer process. Successful exploitation could allow an attacker to perform a sandbox escape, leading to arbitrary code execution on the host operating system. Google has addressed this in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-03-30: disclosed: Reported to Chromium by Google researchers
  • 2026-05-12: patched: Fixed in version 148.0.7778.168
  • 2026-05-14: advisory: NVD publication date

References

Related threats