Junglewise Threat Intelligence

CVE-2026-17658: Google Chrome use after free in V8

CVE-2026-17658 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its V8 JavaScript engine could allow a remote attacker to execute unauthorized code on a user's computer if they visit a specially crafted website. While the attack is limited to the browser's security sandbox, it represents a significant risk to user data and system integrity.

Technical details

A use-after-free (UAF) vulnerability exists in the V8 JavaScript engine within Google Chrome. The flaw is triggered when the engine attempts to access memory that has already been freed, typically during the processing of complex JavaScript or HTML content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, leading to arbitrary code execution within the browser's sandbox environment. This vulnerability was addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-06-12: disclosed: Reported by Duc Nguyen of Calif.io in collaboration with OpenAI Codex Security
  • 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.71/.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats