Executive brief
A security vulnerability exists in the V8 engine of Google Chrome, which is responsible for processing JavaScript. By tricking a user into visiting a specially crafted website, an attacker could cause the browser to crash or potentially execute unauthorized code. This could lead to the theft of sensitive information or the compromise of the user's computer.
Technical details
A race condition (CWE-362) exists in the V8 JavaScript engine component of Google Chrome. The vulnerability is triggered when the engine improperly synchronizes shared resources during concurrent execution, leading to a type confusion state. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page and inducing a user to visit it. Successful exploitation could allow for arbitrary code execution within the context of the browser's renderer process. The issue was addressed in Chrome version 144.0.7559.99.
Affected products
- Google Chrome prior to 144.0.7559.99
Timeline
- 2026-01-07: other: Reported by researcher @p1nky4745
- 2026-01-20: patched: Stable channel update released
- 2026-06-10: disclosed: NVD publication date