CVE-2026-8517 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: May 14, 2026
Google Chrome - Remote Code Execution
Published: May 14, 2026Updated: May 14, 2026Remote Exploitable
Overview
Google Chrome < 148.0.7778.168 contains a use after free caused by object lifecycle issue in WebShare, letting remote attackers execute arbitrary code via crafted HTML page, exploit requires user interaction with specific UI gestures.
Severity & Score
Severity: High
CVSS Score: 8.8
Impact
Remote attackers can execute arbitrary code by tricking users into specific UI gestures, potentially leading to full system compromise.
Mitigation
Update to version 148.0.7778.168 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-8517
- Severity
- High
- CVSS Score
- 8.8
- Type
- use_after_free
- Status
- unconfirmed
CWE
- CWE-664
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H