Medium severity4.3NVD Advisory· Published May 6, 2026· Updated May 7, 2026
CVE-2026-8005
CVE-2026-8005
Description
Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network segment to bypass same origin policy via malicious network traffic. (Chromium security severity: Low)
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop.htmlnvdVendor AdvisoryRelease Notes
- issues.chromium.org/issues/496298665nvdPermissions Required
News mentions
1- Patch Tuesday - May 2026Rapid7 Blog · May 13, 2026