CVE-2026-8001Disclosure(apple / chrome)

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Use After Free in Printing in Google Chrome on Linux, Mac, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • chrome_os
  • linux_kernel
  • macos

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-06); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
chromechrome_oslinux_kernelmacos

1 version affected across 4 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 105-0605-07
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • WindowsForum@windowsforum
    Disclosure

    🚨 CVE-2026-8001 “low severity” but it’s a printing use-after-free to help escape the sandbox. Cool cool—nothing says safe like turning peripherals into an exit strategy. #Windows #Security https://windowsforum.com/threads/cve-2026-8001-chrome-printing-use-after-free-sandbox-escape-risk-patch-fast.416913/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #ChromeSecurity #BrowserSandbox #UseAfterFree #Cve20268001 https://t.co/dZxiCsaPSJ

    Post summary

    The tweet announces CVE‑2026‑8001 as a printing use‑after‑free that can escape the sandbox, noting its low severity but potential risk.

    0000037
    1.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8001 Use After Free in Printing in Google Chrome on Linux, Mac, ChromeOS prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to potenti… https://www.cve.org/CVERecord?id=CVE-2026-8001

    Post summary

    The snippet is a concise CVE record description of a use‑after‑free flaw in Chrome’s printing on Linux, Mac, and ChromeOS versions prior to 148.0.7778.96, with no mention of PoC, exploit, or patch.

    00000122
    57.4K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSgooglechrome_os---
OSlinuxlinux_kernel---

Explore more