Junglewise Threat Intelligence

CVE-2026-17979: Google Chrome race condition in V8

CVE-2026-17979 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its V8 engine could allow a remote attacker to execute code within the browser's restricted sandbox environment if a user visits a specially crafted website. While the impact is limited by the sandbox, it represents a potential security risk for users visiting untrusted sites.

Technical details

A race condition (CWE-362) exists in the V8 JavaScript engine component of Google Chrome. The vulnerability is triggered when the engine improperly synchronizes shared resources during concurrent execution. A remote attacker can exploit this by enticing a user to visit a malicious HTML page, potentially leading to arbitrary code execution within the renderer process sandbox. The issue was addressed in Chrome version 151.0.7922.72. Chromium developers have classified this with a 'Low' security severity.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats