Executive brief
Google Chrome, a widely used web browser, was found to have a security flaw in its V8 JavaScript engine. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to run unauthorized code on the user's computer. While the impact is limited by the browser's security sandbox, it could still lead to unauthorized actions or serve as a stepping stone for further attacks.
Technical details
A use-after-free (UAF) vulnerability exists in the V8 JavaScript engine component of Google Chrome. The flaw is triggered when the engine attempts to access memory that has already been freed, typically during the processing of a malicious HTML page. A remote, unauthenticated attacker can exploit this by hosting a specially crafted website; if a user visits the site, the attacker can execute arbitrary code within the context of the browser's sandbox. This vulnerability was addressed in Google Chrome version 150.0.7871.46.
Affected products
- Google Chrome prior to 150.0.7871.46
Timeline
- 2026-06-30: patched: Stable channel update released for desktop
- 2026-07-01: advisory: NVD publication date