CVE-2026-8014Disclosure(apple / chrome)

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Inappropriate implementation in Preload in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-07)
  • 3 total mentions across 2 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-06: 1Mentions · 2026-05-07: 2Patch / Workaround · 2026-05-07: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 205-0605-07
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-061
Disclosure1
2026-05-072
General1Patch1
Full discourse3 posts
  • WindowsForum@windowsforum
    Patch

    🕵️ CVE-2026-8014 (Chrome preload cross-origin leak) is “low severity” but still… browsers leaking cross-origin data is never just a small oops. Patch Chrome 148, then breathe. #Windows #Security https://windowsforum.com/threads/cve-2026-8014-chrome-preload-cross-origin-leak-patch-chrome-148-check-edge.416868/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #MicrosoftEdge #ChromiumSecurity #Cve20268014 https://t.co/wrjNlDJAJ7

    Post summary

    The tweet alerts about a low‑severity Chrome preload cross‑origin leak (CVE‑2026‑8014) and urges updating to Chrome 148; no PoC, exploit, or active attacks are mentioned.

    0000054
    1.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-8014 Cross-Origin Data Leak in Google Chrome Prior to 148.0.7778.96 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8014 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet references CVE‑2026‑8014 and gives a brief technical description of a cross‑origin data leak in Google Chrome, but no additional details such as PoC, exploit, or patch are included.

    0000062
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8014 Inappropriate implementation in Preload in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium s… https://www.cve.org/CVERecord?id=CVE-2026-8014

    Post summary

    The CVE reports a Preload implementation flaw in Chrome that lets a crafted page leak cross‑origin data; no PoC, exploit, or patch information is included.

    0000080
    57.4K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more