CVE-2026-8533

Google · Chrome

A use-after-free vulnerability in the Accessibility component of Google Chrome may lead to memory corruption and arbitrary code execution.

Executive summary

A high-severity use-after-free vulnerability in Google Chrome’s accessibility component could be exploited for remote code execution.

Vulnerability

The vulnerability lies within the browser's accessibility features. An unauthenticated attacker can exploit this by directing a user to a malicious website.

Business impact

The CVSS score of 8.3 indicates that this vulnerability is a serious concern. Exploitation could result in a loss of system control, potentially compromising corporate data and user privacy.

Remediation

Immediate Action: Update all Google Chrome instances to version 148 or later.

Proactive Monitoring: Review security logs for indicators of memory corruption or unauthorized code execution attempts.

Compensating Controls: Use endpoint protection software to monitor and block suspicious accessibility-related API calls.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Organizations should prioritize the deployment of the latest browser updates to mitigate this vulnerability. Timely patching is necessary to prevent potential exploitation.