Executive brief
Google Chrome is a widely used web browser. A vulnerability in its V8 JavaScript engine could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the exploit is contained within the browser's security sandbox, it represents a significant risk to system integrity and user data privacy.
Technical details
A type confusion vulnerability (CWE-843) exists in the V8 JavaScript engine component of Google Chrome. The flaw is triggered when the engine incorrectly handles objects of incompatible types, which can be exploited by a remote attacker through a specially crafted HTML page. Successful exploitation allows for arbitrary code execution within the Chromium renderer process sandbox. This issue was addressed in Chrome version 150.0.7871.46 and later.
Affected products
- Google Chrome prior to 150.0.7871.46
Timeline
- 2026-06-30: patched: Chrome 151 promoted to stable channel containing fixes for version 150.
- 2026-07-01: disclosed: CVE record published.