CVE-2026-0908Patch(apple / chrome)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple chrome systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Use after free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-03-09); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-09: 1Mentions · 2026-05-21: 1PoC Mentioned / Linked · 2026-05-21: 1Exploit Tool / Code · 2026-05-21: 1Patch / Workaround · 2026-03-09: 1Technical Details · 2026-05-21: 103-0905-21
Signal classification2 categories
Patch
150.0%
Exploit
150.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-091
Patch1
2026-05-211
Exploit1
Full discourse2 posts
  • dbugs@ptdbugs
    Exploit

    Chrome ANGLE Use-After-Free CVE: CVE-2026-0908 PT ID: PT-2026-2855 Vendor: Google Product: Chrome CVSS: 8.8 Credits: n/a Description: Use after free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low) References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-0908 • https://chromereleases.googleblog.com/2026/01/stable-channel-update-for-desktop_13.html • https://issues.chromium.org/issues/452209503 PoC/Exploit: https://github.com/lylzjnqe/CVE-2026-0908-Chrome-0-day-RCE #dbugs_vuln

    Post summary

    CVE-2026-0908 is a use‑after‑free flaw in Chrome's ANGLE component; PoC and exploit code are publicly available, but there is no evidence of active exploitation.

    00001241
    1.2K followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    BSI warns of critical vulns in Chrome/Edge (CVE-2026-0899 to CVE-2026-0908). Update browsers now to block potential attacks. Affects multiple Chromium versions. https://borncity.com/news/browsersicherheit-bsi-warnt-vor-kritischen-luecken-in-chrome-und-edge/

    Post summary

    BSI warns of a series of critical CVEs affecting Chrome/Edge, urging immediate browser updates, but no PoC or exploitation evidence is provided.

    0001033
    55 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more