Junglewise Threat Intelligence

CVE-2026-10022: Google Chrome type confusion in V8 engine via malicious extension

CVE-2026-10022 · Severity: info · CVSS 4.3 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's V8 engine could allow a malicious browser extension to execute unauthorized code. To exploit this, an attacker must first trick a user into installing a specifically crafted malicious extension. While the impact is limited by the browser's security sandbox, it could lead to unauthorized actions or data access within the context of the browser.

Technical details

A type confusion vulnerability exists in the V8 JavaScript engine component of Google Chrome. The flaw is triggered when a user installs and runs a specially crafted Chrome Extension. This allows an attacker to bypass intended memory safety boundaries to execute arbitrary code, though the execution is restricted within the Chrome sandbox environment. The issue is addressed in Chrome version 148.0.7778.216 and later. This vulnerability is categorized by Chromium as Medium severity.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Fixed in Chrome Stable channel update 148.0.7778.216/217
  • 2026-05-28: disclosed

References

Related threats