Patch tracker / CVE reference / CVE-2026-8543
CVE-2026-8543
Medium severity vulnerability, CVSS 5.3.
All about CVE-2026-8543: whether it is exploited, how to fix it, its change history, and the questions admins ask.
Which of your devices are still exposed? Find out free with a full Microsoft 365 audit.
Out of bounds read in FileSystem in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Risk summary
Senserva AI Opinion and rich prompt for CVE-2026-8543
Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.
How to fix CVE-2026-8543
Apply the patched version named in the vendor security advisory. Where a workaround exists, apply it only until the update is deployed, not as a substitute.
Affected products
Common questions about CVE-2026-8543
Is CVE-2026-8543 actively exploited?
It is not currently listed in the CISA Known Exploited Vulnerabilities catalog. That can change: unexploited CVEs regularly get weaponized months after disclosure, which is why patching on your normal cadence matters.
What fixes CVE-2026-8543?
The authoritative fix is in the vendor security advisory. Apply the patched version listed there; the references below link to the CVE record and NVD detail.
Which products are affected by CVE-2026-8543?
Google Chrome.
Can I ask my own AI about CVE-2026-8543?
Yes. This page includes a free, ready-to-paste AI prompt with CVE-2026-8543's key facts: severity, CVSS, CISA KEV status, and the affected products. Copy it into Claude, ChatGPT, or Copilot for a triage plan.
Authoritative references
Every Microsoft CVE and the patches that fix it, ranked by real-world risk: the Microsoft Patch Tracker. The full searchable CVE reference: CVE and vulnerability management.