CVE-2026-8580Disclosure(google / chrome)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch google chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-14); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
chrome

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-14: 3Mentions · 2026-05-15: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-14: 3Technical Details · 2026-05-15: 105-1405-15
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-143
Disclosure3
2026-05-151
Disclosure1
Full discourse4 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Google Chrome Mojo Use After Free Sandbox Escape (CVE-2026-8580) A use-after-free vulnerability in the Mojo framework of Google Chrome prior to version 148.0.7778.168 allows a remote attacker to potentially escape the sandbox via a crafted HTML page. Successful exploitation can bypass Chrome’s sandbox protections and lead to higher-privilege code execution on the system. 👉Affected: Google Chrome Desktop < 148.0.7778.168

    Post summary

    The text announces a use‑after‑free vulnerability (CVE‑2026‑8580) in Chrome’s Mojo framework, explains the risk of sandbox escape and privilege escalation, and advises upgrading to version 148.0.7778.168 or later.

    00020115
    196 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-8580 Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium sec… https://www.cve.org/CVERecord?id=CVE-2026-8580

    Post summary

    CVE-2026-8580 is a use‑after‑free flaw in Chrome’s Mojo engine that could lead to sandbox escape through a crafted HTML page on affected versions prior to 148.0.7778.168.

    00000177
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8580 Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8580

    Post summary

    CVE-2026-8580 describes a use‑after‑free in Chrome’s Mojo component that could allow a sandbox escape through a crafted HTML page; while technical details and severity are noted, no patch or exploit code is included.

    0000064
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-8580 Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sand… CVSS 9.6 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-8580 #Google #CyberSecurity #InfoSec

    Post summary

    A new critical use‑after‑free vulnerability (CVE‑2026‑8580) in Chrome’s Mojo engine has been disclosed with CVSS 9.6; no patch is available yet.

    0000089
    90 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---

Explore more