Google Chrome < 148.0.7778.167 Multiple Vulnerabilities

critical Nessus Plugin ID 314745

Synopsis

A web browser installed on the remote macOS host is affected by multiple vulnerabilities.

Description

The version of Google Chrome installed on the remote macOS host is prior to 148.0.7778.167. It is, therefore, affected by multiple vulnerabilities as referenced in the 2026_05_stable-channel-update-for-desktop_12 advisory.

- Use after free in Extensions in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Medium) (CVE-2026-8587)

- Heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical) (CVE-2026-8509)

- Integer overflow in Skia in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page.
(Chromium security severity: Critical) (CVE-2026-8510)

- Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) (CVE-2026-8511)

- Use after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) (CVE-2026-8512)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Google Chrome version 148.0.7778.167 or later.

See Also

http://www.nessus.org/u?439266d5

https://crbug.com/328109821

https://crbug.com/343352552

https://crbug.com/40057534

https://crbug.com/40061220

https://crbug.com/418273622

https://crbug.com/442860473

https://crbug.com/470646792

https://crbug.com/484986863

https://crbug.com/488728570

https://crbug.com/490229299

https://crbug.com/490353576

https://crbug.com/491422244

https://crbug.com/495405493

https://crbug.com/495417883

https://crbug.com/495902113

https://crbug.com/496217775

https://crbug.com/496231853

https://crbug.com/496302307

https://crbug.com/496395450

https://crbug.com/496526419

https://crbug.com/496639647

https://crbug.com/497292072

https://crbug.com/497594413

https://crbug.com/497975477

https://crbug.com/498892595

https://crbug.com/499052720

https://crbug.com/499154022

https://crbug.com/507356235

https://crbug.com/493310462

https://crbug.com/502636904

https://crbug.com/495108488

https://crbug.com/495782021

https://crbug.com/495939973

https://crbug.com/495948109

https://crbug.com/495999127

https://crbug.com/496393078

https://crbug.com/497531263

https://crbug.com/497830330

https://crbug.com/498400132

https://crbug.com/503619813

https://crbug.com/504106200

https://crbug.com/504185107

https://crbug.com/483956252

https://crbug.com/503425922

https://crbug.com/499565267

https://crbug.com/497928952

https://crbug.com/486536241

https://crbug.com/486761172

https://crbug.com/487795397

https://crbug.com/490222151

https://crbug.com/491930142

https://crbug.com/492350403

https://crbug.com/492812194

https://crbug.com/495247950

https://crbug.com/495314407

https://crbug.com/495530312

https://crbug.com/495857582

https://crbug.com/495890000

https://crbug.com/496415073

https://crbug.com/496524586

https://crbug.com/496627235

https://crbug.com/496645393

https://crbug.com/497066659

https://crbug.com/497095799

https://crbug.com/497151750

https://crbug.com/497486030

https://crbug.com/497531791

https://crbug.com/497632199

https://crbug.com/497821764

https://crbug.com/497985088

https://crbug.com/498322453

https://crbug.com/498376171

https://crbug.com/498706958

https://crbug.com/498715368

https://crbug.com/499131214

https://crbug.com/500033878

https://crbug.com/500052361

https://crbug.com/502978647

https://crbug.com/504629701

Plugin Details

Severity: Critical

ID: 314745

File Name: macosx_google_chrome_148_0_7778_167.nasl

Version: 1.1

Type: Local

Agent: macosx

Published: 5/14/2026

Updated: 5/14/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-8587

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:google:chrome

Required KB Items: installed_sw/Google Chrome

Exploit Ease: No known exploits are available

Patch Publication Date: 5/12/2026

Vulnerability Publication Date: 5/12/2026

Reference Information

CVE: CVE-2026-8509, CVE-2026-8510, CVE-2026-8511, CVE-2026-8512, CVE-2026-8513, CVE-2026-8514, CVE-2026-8515, CVE-2026-8516, CVE-2026-8517, CVE-2026-8518, CVE-2026-8519, CVE-2026-8520, CVE-2026-8521, CVE-2026-8522, CVE-2026-8523, CVE-2026-8524, CVE-2026-8525, CVE-2026-8526, CVE-2026-8527, CVE-2026-8528, CVE-2026-8529, CVE-2026-8530, CVE-2026-8531, CVE-2026-8532, CVE-2026-8533, CVE-2026-8534, CVE-2026-8535, CVE-2026-8536, CVE-2026-8537, CVE-2026-8538, CVE-2026-8539, CVE-2026-8540, CVE-2026-8541, CVE-2026-8542, CVE-2026-8543, CVE-2026-8544, CVE-2026-8545, CVE-2026-8546, CVE-2026-8547, CVE-2026-8548, CVE-2026-8549, CVE-2026-8550, CVE-2026-8551, CVE-2026-8552, CVE-2026-8553, CVE-2026-8554, CVE-2026-8555, CVE-2026-8556, CVE-2026-8557, CVE-2026-8558, CVE-2026-8559, CVE-2026-8560, CVE-2026-8561, CVE-2026-8562, CVE-2026-8563, CVE-2026-8564, CVE-2026-8565, CVE-2026-8566, CVE-2026-8567, CVE-2026-8568, CVE-2026-8569, CVE-2026-8570, CVE-2026-8571, CVE-2026-8572, CVE-2026-8573, CVE-2026-8574, CVE-2026-8575, CVE-2026-8576, CVE-2026-8577, CVE-2026-8578, CVE-2026-8579, CVE-2026-8580, CVE-2026-8581, CVE-2026-8582, CVE-2026-8583, CVE-2026-8584, CVE-2026-8585, CVE-2026-8586, CVE-2026-8587