CVE-2026-8018
Insufficient Policy Enforcement in Google Chrome DevTools
Publication date: 2026-05-06
Last updated on: 2026-05-06
Assigner: Chrome
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| chrome | 148.0.7778.96 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an insufficient policy enforcement issue in the DevTools component of Google Chrome versions prior to 148.0.7778.96. It allows a remote attacker to potentially escape the browser's sandbox by exploiting malicious network traffic.
How can this vulnerability impact me? :
The impact of this vulnerability is that a remote attacker could potentially bypass the sandbox protections of Google Chrome, which are designed to isolate processes and limit the ability of malicious code to affect the system. This could lead to unauthorized access or control beyond the browser environment.