CVE-2026-8007Disclosure(apple / chrome)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-07)
  • 3 total mentions across 2 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-06: 1Mentions · 2026-05-07: 2Patch / Workaround · 2026-05-07: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 105-0605-07
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-061
Disclosure1
2026-05-072
General1Patch1
Full discourse3 posts
  • VulDB 🛡@vuldb
    General

    The severity is increased for this new vulnerability affecting Google Chrome (CVE-2026-8007) https://vuldb.com/vuln/361689

    Post summary

    The tweet merely notes that the severity of CVE-2026-8007 has increased, linking to a generic vulnerability page, without providing any technical details, PoC, exploitation evidence, or patch information.

    0101067
    2.1K followersView on X
  • WindowsForum@windowsforum
    Patch

    🪟 CVE-2026-8007: “low severity” Chrome Cast validation… but it escalates privileges after renderer compromise. Translation: one sketchy page, then game over. Patch it. #Windows #Security https://windowsforum.com/threads/cve-2026-8007-chrome-cast-validation-flaw-what-windows-admins-must-patch.416895/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #MicrosoftEdge #ChromeSecurity #WindowsPatching #Cve20268007 https://t.co/iM9psgcMmN

    Post summary

    The tweet warns that CVE‑2026‑8007 is a low‑severity flaw in Chrome Cast validation that can lead to privilege escalation, and urges users to apply the patch.

    0000058
    1.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8007 Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform… https://www.cve.org/CVERecord?id=CVE-2026-8007

    Post summary

    The text reports CVE‑2026‑8007 as a Chrome Cast validation flaw affecting versions prior to 148.0.7778.96, describing the vulnerability type but providing no PoC, exploit, or patch details.

    00000113
    57.4K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more