Junglewise Threat Intelligence

CVE-2026-10989: Google Chrome V8 heap corruption via UI gestures

CVE-2026-10989 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's V8 engine could allow a remote attacker to corrupt the browser's memory. To exploit this, an attacker would need to trick a user into visiting a malicious website and performing specific interactions or gestures. Successful exploitation could lead to browser crashes or potentially allow the attacker to execute unauthorized code on the user's system.

Technical details

This vulnerability is classified as an 'Inappropriate implementation' within the V8 JavaScript engine, leading to potential heap corruption. The flaw is reachable via a crafted HTML page, though it requires a precondition where the attacker must convince a user to engage in specific UI gestures. If successfully triggered, the heap corruption could be leveraged for remote code execution within the context of the browser renderer process. The issue was addressed in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: NVD publication date

References

Related threats