Junglewise Threat Intelligence

CVE-2026-8579: Google Chrome out of bounds memory write in Skia

CVE-2026-8579 · Severity: low · CVSS 3.1 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's graphics engine, Skia, contains a vulnerability that could allow an attacker to write data to restricted memory areas. This issue occurs when the browser processes a specially crafted print file. If exploited, an attacker who has already gained a foothold in the browser's rendering process could potentially cause the application to crash or execute unauthorized actions.

Technical details

An out-of-bounds (OOB) memory write vulnerability exists in the Skia graphics component of Google Chrome. The flaw is caused by insufficient validation of untrusted input when handling print files. To exploit this, a remote attacker must first compromise the renderer process. Once achieved, they can use a specially crafted print file to trigger the OOB write. This could lead to memory corruption or further escalation of privileges within the sandboxed environment. The issue is addressed in Chrome version 148.0.7778.168.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-05-12: patched: Chrome Stable Channel Update released
  • 2026-05-14: disclosed: NVD publication date

References

Related threats