Junglewise Threat Intelligence

CVE-2026-10910: Google Chrome Type Confusion in V8

CVE-2026-10910 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its V8 JavaScript engine could allow a malicious website to execute unauthorized code on a user's computer. While this code is restricted to the browser's security sandbox, it could lead to data theft or be combined with other flaws to compromise the entire system.

Technical details

A type confusion vulnerability (CWE-843) exists in the V8 JavaScript engine component of Google Chrome. The flaw is triggered when the engine incorrectly processes objects of incompatible types, which can be exploited by a remote attacker who entices a user to visit a specially crafted HTML page. Successful exploitation allows for arbitrary code execution within the context of the Chromium renderer sandbox. The issue was resolved in version 149.0.7827.53 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-05-02: disclosed: Reported by Mufeed VH from Winfunc Research
  • 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable channel update
  • 2026-06-04: advisory: CVE published in NVD dataset

References

Related threats