Executive brief
A security vulnerability has been identified in Google Chrome's V8 engine, which is responsible for processing JavaScript. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially allowing the attacker to execute unauthorized code on the user's computer. While the exploit is limited to the browser's security sandbox, it represents a significant risk to data privacy and system integrity.
Technical details
A type confusion vulnerability (CWE-843) exists in the V8 JavaScript engine within Google Chrome. The flaw stems from an inappropriate implementation that allows a remote, unauthenticated attacker to achieve arbitrary code execution within the browser's sandbox. Exploitation requires a user to navigate to a malicious or compromised web page (User Interaction). The vulnerability was addressed in Chrome version 150.0.7871.125 for Windows and Mac, and 150.0.7871.124 for Linux.
Affected products
- Google Chrome Prior to 150.0.7871.125
Timeline
- 2026-07-08: disclosed: Reported to Chromium by Salvatore Gulizia
- 2026-07-14: patched: Stable channel update released
- 2026-07-14: advisory: NVD publication date