LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-8517 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: May 14, 2026

Google Chrome - Remote Code Execution

Published: May 14, 2026Updated: May 14, 2026Remote Exploitable

Overview

Google Chrome < 148.0.7778.168 contains a use after free caused by object lifecycle issue in WebShare, letting remote attackers execute arbitrary code via crafted HTML page, exploit requires user interaction with specific UI gestures.

Severity & Score

Severity: High
CVSS Score: 8.8

Impact

Remote attackers can execute arbitrary code by tricking users into specific UI gestures, potentially leading to full system compromise.

Mitigation

Update to version 148.0.7778.168 or later.

Details

CVE ID
CVE-2026-8517
Severity
High
CVSS Score
8.8
Type
use_after_free
Status
unconfirmed

CWE

  • CWE-664

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H