Junglewise Threat Intelligence

CVE-2026-8569: Google Chrome out of bounds write in Codecs on macOS

CVE-2026-8569 · Severity: high · CVSS 8.3 · Published 2026-05-14

Technologies: Apple macOS, Google Chrome. Vendors: Apple, Google.

Executive brief

A vulnerability in Google Chrome's video processing components on macOS could allow a remote attacker to bypass security restrictions. By tricking a user into opening a specially crafted video file, an attacker could potentially escape the browser's protective 'sandbox' to gain unauthorized access to the underlying operating system. This poses a significant risk to data confidentiality and system integrity on affected Mac devices.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists within the Codecs component of Google Chrome on macOS. The flaw is triggered when the browser processes a specially crafted video file, leading to memory corruption. A remote attacker can exploit this by hosting a malicious video file and enticing a user to visit a site that loads it. Successful exploitation could allow the attacker to escape the Chromium sandbox and execute arbitrary code with the privileges of the user on the host operating system. The issue is resolved in Chrome version 148.0.7778.168 for Mac.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-03-06: other: Reported by Google researchers
  • 2026-05-12: patched: Fixed in version 148.0.7778.168
  • 2026-05-14: disclosed: NVD publication date

References

Related threats