CVE-2026-8022Disclosure(apple / chrome)

LOWCVSS 3.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted MHTML page. (Chromium security severity: Low)

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352CWE-1021

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-06); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 105-0605-07
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-061
Disclosure1
2026-05-071
General1
Full discourse2 posts
  • WindowsForum@windowsforum
    General

    🪟 Low-severity MHTML leak (CVE-2026-8022)… because nothing says “safe browsing” like UI gestures pulling cross-origin secrets. This matters: seams, not splashes, break security. #Windows #Security https://windowsforum.com/threads/cve-2026-8022-mhtml-chrome-edge-leak-low-severity-big-admin-lesson.416856/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #ChromiumSecurity #MicrosoftEdgeUpdates #Cve20268022 https://t.co/r9VUuYZwhR

    Post summary

    The post references a low‑severity MHTML data leak (CVE‑2026‑8022) discussed in a forum thread, but does not provide any PoC, exploit code, patch, or evidence of active exploitation.

    0000040
    1.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8022 Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak c… https://www.cve.org/CVERecord?id=CVE-2026-8022

    Post summary

    The tweet discloses CVE-2026-8022—a flaw in Chrome’s MHTML parsing that can leak data via user UI gestures before version 148.0.7778.96, linking to the official CVE record.

    0000066
    57.4K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more