Executive brief
A vulnerability in Google Chrome's V8 engine could allow an attacker to execute malicious code on a user's computer. This occurs if a user visits a specially crafted website using an affected version of the browser. While the exploit is limited to the browser's security sandbox, it could be combined with other flaws to compromise the entire system or access sensitive user data.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the V8 JavaScript engine component of Google Chrome. The flaw can be triggered by a remote attacker who lures a user to a malicious HTML page. Successful exploitation requires the attacker to have already compromised the renderer process, at which point they can achieve arbitrary code execution within the browser's sandbox environment. This vulnerability was addressed in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome Stable Channel Update released version 149.0.7827.53
- 2026-06-04: disclosed: NVD publication date