Junglewise Threat Intelligence

CVE-2026-17948: Google Chrome type confusion in V8 engine

CVE-2026-17948 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's V8 engine could allow a malicious browser extension to execute unauthorized code. To be successful, an attacker must first trick a user into installing a specifically crafted malicious extension. While the code execution is restricted within a security sandbox, it represents a breakdown in the browser's internal security boundaries.

Technical details

A type confusion vulnerability exists in the V8 JavaScript engine component of Google Chrome. The flaw (CWE-843) occurs when the engine accesses a resource using an incompatible type, which can be triggered by a specially crafted Chrome Extension. An attacker who successfully induces a user to install such an extension can achieve arbitrary code execution within the browser's sandbox environment. This issue was addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux. The vulnerability is classified by Chromium as Low severity because it requires the installation of a malicious extension as a precondition.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats