Junglewise Threat Intelligence

CVE-2026-17725: Google Chrome type confusion in V8

CVE-2026-17725 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contains a security vulnerability in its V8 JavaScript engine. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to run unauthorized code on the user's computer. While the browser's security sandbox provides some protection, this flaw could lead to data theft or further system compromise if combined with other vulnerabilities.

Technical details

A type confusion vulnerability exists in the V8 JavaScript engine within Google Chrome. The flaw is rooted in the 'Access of Resource Using Incompatible Type' (CWE-843) during the processing of JavaScript code. A remote, unauthenticated attacker can exploit this by inducing a user to load a malicious HTML page. Successful exploitation allows for arbitrary code execution within the context of the browser's sandbox. Google has addressed this in version 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.71/.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats