Junglewise Threat Intelligence

CVE-2026-8573: Google Chrome integer overflow in Codecs

CVE-2026-8573 · Severity: high · CVSS 8.3 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's video processing components could allow a remote attacker to bypass security protections. By tricking a user into opening a specially crafted video file, an attacker could potentially escape the browser's 'sandbox,' which is designed to keep malicious code from affecting the rest of the computer. This could lead to unauthorized access to the user's system and data.

Technical details

An integer overflow vulnerability exists in the Codecs component of Google Chrome for Windows. The flaw is triggered when the browser processes a specially crafted video file, leading to memory corruption. A remote attacker can exploit this by hosting a malicious video file and inducing a user to view it. Successful exploitation could allow the attacker to escape the Chromium sandbox and execute arbitrary code with the privileges of the user on the underlying Windows operating system. The issue is addressed in Chrome version 148.0.7778.168.

Affected products

  • Google Chrome Prior to 148.0.7778.168 on Windows

Timeline

  • 2026-05-12: patched: Chrome Stable channel update released for Windows.
  • 2026-05-14: disclosed: CVE published to NVD.

References

Related threats