CVE-2026-8572Disclosure(google / android)

LOWCVSS 3.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Insufficient policy enforcement in Network in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android
  • chrome

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-05-15)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
androidchrome

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-14: 1Mentions · 2026-05-15: 2Technical Details · 2026-05-14: 1Technical Details · 2026-05-15: 205-1405-15
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-141
Disclosure1
2026-05-152
Disclosure2
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8572 Cross-Origin Data Leak in Google Chrome Android Prior to 148.0.7778.168 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8572

    Post summary

    The post announces CVE-2026-8572, a cross‑origin data leak in older Google Chrome Android builds, presenting only basic disclosure information without PoC, exploit details, or patch guidance.

    0000164
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-8572 Insufficient policy enforcement in Network in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to lea… https://www.cve.org/CVERecord?id=CVE-2026-8572 ----- Traducción: CVE-2026-8572 Fal… http://infoflow.cloud`

    Post summary

    A short disclosure of CVE‑2026‑8572, describing its insufficient policy enforcement in Chrome for Android and linking to the CVE record.

    0000049
    78 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8572 Insufficient policy enforcement in Network in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to lea… https://www.cve.org/CVERecord?id=CVE-2026-8572

    Post summary

    A new vulnerability (CVE-2026-8572) affecting Chrome on Android is disclosed, detailing insufficient policy enforcement that could allow remote exploitation if the renderer process is compromised.

    00000222
    57.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid---
Appgooglechrome---

Explore more