CVE-2026-8560
published 2026-05-14CVE-2026-8560: Heap buffer overflow in SwiftShader in Google Chrome on Mac and iOS prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory read…
PriorityP420medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
0.25%
16.6th percentile
Heap buffer overflow in SwiftShader in Google Chrome on Mac and iOS prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 148.0.7778.168 | 148.0.7778.168 | |
| chrome | >= 148.0.7778.168 < 148.0.7778.168 | 148.0.7778.168 | |
| chrome_desktop | — | — | |
| paloalto | prisma_browser | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 148.0.7778.96 on macOS SwiftShader heap-based overflow (ID 328109 / Nessus ID 314864)
vuldb·2026-05-17·CVSS 4.3
CVE-2026-8560 [MEDIUM] Google Chrome up to 148.0.7778.96 on macOS SwiftShader heap-based overflow (ID 328109 / Nessus ID 314864)
A vulnerability, which was classified as critical, has been found in Google Chrome on macOS. This issue affects some unknown processing of the component SwiftShader. Performing a manipulation results in heap-based buffer overflow.
This vulnerability is identified as CVE-2026-8560. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
GHSA
GHSA-5cf7-j3cg-f6cx: Heap buffer overflow in SwiftShader in Google Chrome on Mac and iOS prior to 148
ghsa_unreviewed·2026-05-14
CVE-2026-8560 [MEDIUM] CWE-122 GHSA-5cf7-j3cg-f6cx: Heap buffer overflow in SwiftShader in Google Chrome on Mac and iOS prior to 148
Heap buffer overflow in SwiftShader in Google Chrome on Mac and iOS prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Palo Alto
PAN-SA-2026-0008 Chromium: Monthly Vulnerability Update (June 2026)
vendor_paloalto·2026-06-10·CVSS 8.8
CVE-2026-8509 [HIGH] PAN-SA-2026-0008 Chromium: Monthly Vulnerability Update (June 2026)
PAN-SA-2026-0008 Chromium: Monthly Vulnerability Update (June 2026)
Palo Alto Networks incorporated the following Chromium security fixes into our products: https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop.html https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0877304591.html https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_12.html CVE Summary CVE-2026-8509 Heap buffer overflow in WebML CVE-2026-8510 Integer overflow in Skia CVE-2026-8511 Use after free in UI CVE-2026-8512 Use after free in FileSystem CVE-2026-8513 Use after free in Input CVE-2026-8514 Use after free in Aura CVE-2026-8515 Use after free
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-8560
vendor_chrome·2026-05-19·CVSS 4.3
CVE-2026-8560 [MEDIUM] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-8560
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2026-8560
Chrome
Stable Channel Update for Desktop: CVE-2026-8559
vendor_chrome·2026-05-12·CVSS 4.3
CVE-2026-8559 [HIGH] Stable Channel Update for Desktop: CVE-2026-8559
Stable Channel Update for Desktop
CVE-2026-8559: Integer overflow in Internationalization. Reported by Google on 2026-04-20 [TBD][ 328109821 ] Medium CVE-2026-8560: Heap buffer overflow in SwiftShader
Reported by Cassidy Kim(@cassidy6564) on 2024-03-05 [TBD][ 343352552 ] Medium CVE-2026-8561: Incorrect security UI in Fullscreen
Severity: high
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-14
Published