Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6273-1 | chromium security update |
Fri, 15 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Use‑after‑Free in Chrome Extensions Allows Arbitrary Code Execution on macOS | chromium-browser: chromium-browser: Use after free in Extensions |
| Weaknesses | CWE-825 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 14 May 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Use‑after‑Free in Chrome Extensions Allows Arbitrary Code Execution on macOS |
Thu, 14 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google chrome |
|
| Vendors & Products |
Google
Google chrome |
Thu, 14 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 14 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Use after free in Extensions in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Medium) | |
| Weaknesses | CWE-416 | |
| References |
|
Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2026-05-15T03:56:23.086Z
Reserved: 2026-05-14T05:40:28.363Z
Link: CVE-2026-8587
Updated: 2026-05-14T20:35:19.958Z
Status : Awaiting Analysis
Published: 2026-05-14T20:17:21.083
Modified: 2026-05-14T21:19:23.923
Link: CVE-2026-8587
OpenCVE Enrichment
Updated: 2026-05-15T15:00:14Z
Debian DSA