CVE-2026-8016Disclosure(apple / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-05-07)
  • 4 total mentions across 2 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-06: 1Mentions · 2026-05-07: 3Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 105-0605-07
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-061
Disclosure1
2026-05-073
Disclosure2General1
Full discourse4 posts
  • WindowsForum@windowsforum
    General

    🚨 CVE-2026-8016 says “Low,” but CISA says “High.” That’s the real bug: mismatched scoring chaos. It matters because IT won’t patch what doesn’t scare them. #Windows #Security https://windowsforum.com/threads/cve-2026-8016-webrtc-use-after-free-fix-priority-despite-low-label.416874/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #WebrtcVulnerability #BrowserPatchManagement #Cve20268016 #ChromeAndEdgeSecurity https://t.co/zcR1aYrdky

    Post summary

    The tweet points out a scoring mismatch between the CVE’s low score and CISA’s high rating, warning that this could delay patching, but it offers no technical, exploit, or patch details.

    0000037
    1.1K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Google Chrome (CVE-2026-8016) https://vuldb.com/vuln/361698

    Post summary

    The post announces the disclosure of CVE-2026-8016 affecting Google Chrome, providing no further technical details, exploits, or mitigation information.

    0000061
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8016 Use After Free in WebRTC in Google Chrome Prior to 148.0.7778.96 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8016

    Post summary

    A use-after-free vulnerability (CVE-2026-8016) exists in WebRTC for Google Chrome prior to version 148.0.7778.96; the post provides technical details but no PoC, exploit, or patch information.

    0000059
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8016 Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium… https://www.cve.org/CVERecord?id=CVE-2026-8016

    Post summary

    The excerpt details a newly disclosed use‑after‑free vulnerability in Chrome’s WebRTC that could enable remote code execution via crafted HTML pages, but it does not provide evidence of real‑world exploitation or mitigation measures.

    0000081
    57.4K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more