Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4350 articles · 196587 vulns · 37/41 feeds (7d)
← Back to list
8.3
CVE-2026-8512PATCHED
google · chrome

CVE-2026-8512: Use after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to

Description

Use after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Affected Products

VendorProductVersions
googlechrome148.0.7778.168

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
applemacoscve_cpe95%
googlechromecert_advisory90%
linuxlinux_kernelcve_cpe95%
microsoftwindowscve_cpe95%

References

  • https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_12.html
  • https://issues.chromium.org/issues/495782021

Related News (5 articles)

Tier D
CSO Online17d ago
Human oversight is still critical as AI patching tools miss security risks
→ No new info (linked only)
Tier D
Help Net Security18d ago
Three in four AI-generated vulnerability patches leave something broken
→ No new info (linked only)
Tier B
CERT-FR98d ago
Multiples vulnérabilités dans Microsoft Edge (18 mai 2026)
→ No new info (linked only)
Tier B
BSI Advisories101d ago
[NEU] [hoch] Google Chrome: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB101d ago
CVE-2026-8512 | Google Chrome up to 148.0.7778.96 Fileystem use after free (ID 495782)
→ No new info (linked only)
CVSS 3.18.3 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
148.0.7778.168
CWECWE-416
PublishedMay 14, 2026
Last enriched101d agov2
Trending Score8
Source articles5
Independent5
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-76035
CVE-2026-76035: Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to ex
Trending: 33
HIGHCVE-2026-76020
CVE-2026-76020: Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside
Trending: 31
HIGHCVE-2026-76045
CVE-2026-76045: Use after free in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code ins
Trending: 31
HIGHCVE-2026-76037
CVE-2026-76037: Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to
Trending: 31
HIGHCVE-2026-76044
CVE-2026-76044: Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the rendere
Trending: 31

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 14, 2026
Discovered by ZDM
May 14, 2026
Updated: affectedVersions, severity
May 15, 2026
Patch Available
May 15, 2026

Version History

v2
Last enriched 101d ago
v2Tier C101d ago

Updated affected versions to 148.0.7778.96 and changed severity to CRITICAL.

affectedVersionsseverity
via VulDB
v1101d ago

Initial creation