CVE-2026-8514: Critical Use after free in Aura
Chromium: CVE-2026-8514 Use after free in Aura
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information
— Microsoft
Use after free in Aura in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Chromium / Google Chrome (Aura)to a version that resolves this vulnerability.Fixed in 148.0.7778.168 - Compensating control
Mitigate exposure by reducing the risk of renderer-process compromise until browsers are updated (e.g., avoid opening untrusted/crafted HTML pages from untrusted sources).
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-8514?
CVE-2026-8514 has been rated as a high-severity vulnerability due to its potential for exploitation through a use after free in Aura.
How do I fix CVE-2026-8514?
To fix CVE-2026-8514, users should update Google Chrome to version 148.0.7778.167 or later, or Microsoft Edge (Chromium-based) as per their vendor's guidelines.
What software versions are affected by CVE-2026-8514?
CVE-2026-8514 affects Google Chrome versions prior to 148.0.7778.167 and Microsoft Edge (Chromium-based) versions prior to their latest updates as outlined by Microsoft.
Is CVE-2026-8514 exploitable by remote attackers?
Yes, due to the nature of the use after free vulnerability in CVE-2026-8514, it can potentially be exploited by remote attackers.
Which products should I be concerned about with CVE-2026-8514?
Users of Google Chrome prior to version 148.0.7778.167 and Microsoft Edge (Chromium-based) are the primary products that should be monitored for CVE-2026-8514.