Junglewise Threat Intelligence

CVE-2026-10936: Google Chrome type confusion in V8

CVE-2026-10936 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's V8 engine allows a remote attacker to execute arbitrary code on a user's computer. This occurs when a user visits a specially crafted website. While the exploit is contained within the browser's security sandbox, it could be combined with other flaws to compromise the entire system or access sensitive user data.

Technical details

A type confusion vulnerability (CWE-843) exists in the V8 JavaScript engine component of Google Chrome. The flaw is triggered when the engine incorrectly handles objects of incompatible types during execution. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website containing a specially crafted HTML page. Successful exploitation allows for arbitrary code execution within the context of the browser's sandboxed process. The issue is resolved in Google Chrome version 149.0.7827.53 and later.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-14: disclosed: Reported to Chrome by Google internal researchers
  • 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable channel update
  • 2026-06-04: advisory: NVD publication date

References

Related threats