CVEFinder.io

CVE-2026-8534

âš ī¸ high
🔍 Scan for this CVE
Summary

Integer overflow in GPU in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS Score
8.3
High
EPSS Score
0.1
Exploit Probability
Published Date
2026-05-14
First Seen: 2026-05-17
📊 Relative Risk Intelligence

This CVE is High Risk - more severe than 79.2% of all 355,915 vulnerabilities in our database.

#74,128
Top 25% most severe
Severity Percentile
đŸŽ¯ CISA SSVC Assessment Updated: May 14, 2026
🔍 Exploitation Status
None
No known exploits
âš™ī¸ Automatable
NO
Requires human interaction
đŸ’Ĩ Technical Impact
Total
Complete system compromise possible
SSVC data provided by CISA
Last Modified 2026-05-19
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
CWE IDs (Weakness Types)

đŸ“Ļ Affected Products 1

🔗 References 2

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-87429 đŸ”ļ medium 6.5 0.3 Missing authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had comprom... 2026-09-09
CVE-2026-87430 âš ī¸ high 8.8 0.5 Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbit... 2026-09-09
CVE-2026-87431 âš ī¸ high 7.5 0.3 Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitiv... 2026-09-09
CVE-2026-87432 đŸ”ļ medium 4.2 0.2 Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromi... 2026-09-09
CVE-2026-87433 âš ī¸ high 8.8 0.2 Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the rend... 2026-09-09
CVE-2026-87434 â„šī¸ low 3.1 0.3 Missing authorization in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the ... 2026-09-09
These CVEs affect the same products