Executive brief
Google Chrome is a widely used web browser for accessing the internet and running web applications. A security vulnerability has been identified in its V8 JavaScript engine that could allow a malicious website to execute unauthorized code on a user's computer. While the exploit is limited to the browser's security sandbox, it represents a significant risk to data privacy and system integrity if combined with other flaws.
Technical details
A use-after-free (UAF) vulnerability exists in the V8 JavaScript engine component of Google Chrome. The flaw is triggered when the engine attempts to access memory that has already been freed, typically during the processing of complex JavaScript objects or heap operations. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows for arbitrary code execution (ACE) within the context of the Chromium sandbox. Google has addressed this issue in version 150.0.7871.46 and later.
Affected products
- Google Chrome prior to 150.0.7871.46
Timeline
- 2026-06-30: patched: Stable channel update released for desktop.
- 2026-07-01: advisory: NVD published the CVE record.