Junglewise Threat Intelligence

CVE-2026-15776: Google Chrome type confusion in V8

CVE-2026-15776 · Severity: high · CVSS 8.8 · Published 2026-07-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Chrome's V8 engine, which is responsible for processing JavaScript. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially allowing the attacker to execute unauthorized code on the user's computer. While the exploit is limited to the browser's security sandbox, it represents a significant risk to data privacy and system integrity.

Technical details

A type confusion vulnerability (CWE-843) exists in the V8 JavaScript engine within Google Chrome. The flaw stems from an inappropriate implementation that allows a remote, unauthenticated attacker to achieve arbitrary code execution within the browser's sandbox. Exploitation requires a user to navigate to a malicious or compromised web page (User Interaction). The vulnerability was addressed in Chrome version 150.0.7871.125 for Windows and Mac, and 150.0.7871.124 for Linux.

Affected products

  • Google Chrome Prior to 150.0.7871.125

Timeline

  • 2026-07-08: disclosed: Reported to Chromium by Salvatore Gulizia
  • 2026-07-14: patched: Stable channel update released
  • 2026-07-14: advisory: NVD publication date

References

Related threats