Executive brief
A vulnerability exists in Google Chrome's V8 engine, which is responsible for processing JavaScript. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to execute unauthorized code on the user's device. While the impact is limited by the browser's security sandbox, it still poses a risk to the integrity of the browsing session.
Technical details
This vulnerability is a use-after-free (UAF) class issue residing in the V8 JavaScript engine component of Google Chrome. The flaw is triggered when the engine attempts to access memory that has already been freed, which can be induced by a remote attacker through a specifically crafted HTML page. Successful exploitation allows for arbitrary code execution (ACE) within the context of the Chromium renderer sandbox. The vulnerability was addressed in Chrome version 150.0.7871.46 for Linux and 150.0.7871.46/.47 for Windows and Mac. Google classifies the severity of this specific V8 issue as Low.
Affected products
- Google Chrome Prior to 150.0.7871.46
Timeline
- 2026-06-30: patched: Stable channel update released for desktop.
- 2026-07-01: advisory: NVD published the CVE record.