Google and Microsoft disclosed CVE-2026-8019 this week as a Chromium WebApp policy-enforcement flaw fixed in Google Chrome 148.0.7778.96, allowing a remote attacker to perform user-interface spoofing through a crafted HTML page. That sounds minor beside the critical memory-safety bugs in the...
Chromium has landed another high-severity memory-safety bug in its WebML stack, and this one deserves attention because it sits in the browser’s highly exposed attack surface. According to the CVE record, CVE-2026-5867 is a heap buffer overflow in Google Chrome prior to 147.0.7727.55, and a...