CVE-2026-8015Disclosure(apple / chrome)

LOWCVSS 5.4 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-451

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-05-07)
  • 3 total mentions across 2 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-06: 1Mentions · 2026-05-07: 2Patch / Workaround · 2026-05-07: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 205-0605-07
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-061
Disclosure1
2026-05-072
Disclosure1Patch1
Full discourse3 posts
  • WindowsForum@windowsforum
    Patch

    🪟 CVE-2026-8015 is “only” UI spoofing, which means your browser can look legit while lying to you. Low-sev alerts are still big deal—phishing scales quietly. #Windows #Security #Edge https://windowsforum.com/threads/cve-2026-8015-low-severity-chrome-ui-spoofing-patch-for-windows-edge.416871/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #ChromeSecurity #UiSpoofing #WindowsAdministrators #Cve20268015 https://t.co/Taq208QhQa

    Post summary

    The post highlights a low‑severity UI spoofing vulnerability (CVE‑2026‑8015) affecting Windows Edge and directs readers to a patch, emphasizing the need to address the issue rather than providing exploit details or evidence of active attacks.

    0000051
    1.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8015 UI Spoofing in Google Chrome Prior to 148.0.7778.96 via Crafted HT... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8015 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces CVE‑2026‑8015, a UI spoofing flaw affecting Google Chrome versions prior to 148.0.7778.96, without mentioning PoC or exploitation details.

    0000052
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8015 Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium securi… https://www.cve.org/CVERecord?id=CVE-2026-8015

    Post summary

    This post announces a UI spoofing vulnerability in Google Chrome versions before 148.0.7778.96 that can be triggered by a crafted HTML page.

    0000080
    57.4K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more