Junglewise Threat Intelligence

CVE-2026-10963: Google Chrome integer overflow in V8 engine

CVE-2026-10963 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

An integer overflow vulnerability exists in the V8 JavaScript engine used by Google Chrome. This flaw allows a remote attacker to execute malicious code on a user's computer if the user visits a specially crafted website. While the exploit is contained within the browser's security sandbox, it could lead to unauthorized data access or be used as part of a larger attack to compromise the host system.

Technical details

An integer overflow vulnerability exists in the V8 JavaScript engine within Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the engine processes specifically crafted JavaScript or HTML content, leading to memory corruption. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, resulting in arbitrary code execution within the context of the browser's sandbox. This vulnerability is classified by Chromium as High severity and is addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome version 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE published in NVD.

References

Related threats