Junglewise Threat Intelligence

CVE-2026-8578: Google Chrome out of bounds read in GPU on Linux

CVE-2026-8578 · Severity: low · CVSS 3.1 · Published 2026-05-14

Technologies: Google Chrome, Linux Kernel. Vendors: Google, Linux.

Executive brief

A vulnerability in the Google Chrome web browser on Linux could allow a malicious website to access sensitive data from other websites. This occurs when a user visits a specially crafted page, potentially allowing an attacker who has already partially compromised the browser's internal processes to bypass security boundaries. This could lead to the unauthorized exposure of personal information or login session data.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the GPU component of Google Chrome for Linux. The flaw is reachable by a remote attacker who has already compromised the renderer process. By enticing a user to visit a specially crafted HTML page, the attacker can exploit this memory safety issue to read data outside of the intended buffer, leading to the leakage of cross-origin information. The vulnerability was addressed in version 148.0.7778.168.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-05-12: patched: Stable channel update released for desktop.
  • 2026-05-14: disclosed: CVE published to NVD.

References

Related threats