Cross-Origin Data Leak in Google Chrome for Linux and ChromeOS
CVE-2026-8576

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
14 May 2026

What is CVE-2026-8576?

A vulnerability in Google Chrome's Cross-Origin Resource Sharing (CORS) implementation for Linux and ChromeOS versions prior to 148.0.7778.168 allows remote attackers to exploit this flaw and access sensitive cross-origin data through specially crafted HTML pages. This could lead to unauthorized information disclosure, posing significant risks for users accessing vulnerable web content.

Affected Version(s)

Chrome 148.0.7778.168

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.