Executive brief
Google Chrome is a widely used web browser. A security vulnerability was identified in its V8 engine that could allow a remote attacker to execute unauthorized code on a user's computer if they are tricked into performing specific interactions on a malicious website. While the impact is limited by the browser's security sandbox, it could still lead to unauthorized actions within the browser environment.
Technical details
This vulnerability is classified as an 'inappropriate implementation' within the V8 JavaScript engine of Google Chrome. The flaw allows a remote attacker to achieve arbitrary code execution within the renderer process sandbox. Exploitation requires a precondition where the attacker must convince a user to engage in specific UI gestures while visiting a specially crafted HTML page. The issue was addressed in Chrome version 150.0.7871.46. Chromium developers have assigned this a 'Low' severity rating.
Affected products
- Google Chrome prior to 150.0.7871.46
Timeline
- 2026-06-30: patched: Chrome 150.0.7871.46 released to stable channel
- 2026-07-01: advisory: NVD publication date