Junglewise Threat Intelligence

CVE-2026-10964: Google Chrome integer overflow in V8

CVE-2026-10964 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome web browser could allow an attacker to execute malicious code on a user's computer. This occurs when a user visits a specially crafted website designed to trigger a memory error in the browser's JavaScript engine. While the exploit is contained within the browser's security sandbox, it could lead to browser crashes or be used as part of a larger attack to compromise the system or steal data.

Technical details

An integer overflow vulnerability exists in the V8 JavaScript engine component of Google Chrome. The flaw is triggered when the engine processes specifically crafted JavaScript content within an HTML page. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, leading to memory corruption. Successful exploitation allows for arbitrary code execution within the context of the Chromium renderer sandbox. This issue was addressed in Chrome version 149.0.7827.53 for Linux and 149.0.7827.53/.54 for Windows and Mac.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome stable channel update released
  • 2026-06-04: disclosed: CVE published

References

Related threats