Junglewise Threat Intelligence

CVE-2026-8559: Google Chrome integer overflow in Internationalization

CVE-2026-8559 · Severity: medium · CVSS 4.3 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its internationalization component could allow a remote attacker to perform unauthorized memory operations if a user visits a specially crafted website. This could lead to browser instability or potentially allow for further exploitation of the user's system.

Technical details

An integer overflow vulnerability exists in the Internationalization component of Google Chrome for Windows. The flaw is triggered when the browser processes a specially crafted HTML page, leading to an out-of-bounds (OOB) memory write. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website. Successful exploitation could allow the attacker to corrupt memory, potentially leading to a process crash or arbitrary code execution within the context of the browser's sandbox. The issue is addressed in version 148.0.7778.168 for Windows.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-04-20: disclosed: Reported by Google internal researchers
  • 2026-05-12: patched: Fixed in Stable Channel Update 148.0.7778.168
  • 2026-05-14: advisory: NVD publication date

References

Related threats