Executive brief
Google Chrome is a widely used web browser. A security vulnerability in its V8 JavaScript engine could allow a malicious website to execute unauthorized code on a user's computer. While the exploit is limited to the browser's security sandbox, it could lead to data theft or be combined with other flaws to compromise the entire system.
Technical details
A type confusion vulnerability exists in the V8 JavaScript engine within Google Chrome. The flaw is rooted in an 'inappropriate implementation' within the engine's logic. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to achieve arbitrary code execution (ACE) within the context of the browser's sandboxed process. The issue is resolved in Chrome version 149.0.7827.53 and later.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-04-12: other: Reported to Chrome by Google researchers
- 2026-06-02: patched: Stable channel update released
- 2026-06-04: disclosed: NVD publication date