Executive brief
Google Chrome is a widely used web browser. A vulnerability in its V8 engine could allow a remote attacker to execute code within the browser's restricted sandbox environment if a user visits a specially crafted website. While the impact is limited by the sandbox, it represents a potential security risk for users visiting untrusted sites.
Technical details
A race condition (CWE-362) exists in the V8 JavaScript engine component of Google Chrome. The vulnerability is triggered when the engine improperly synchronizes shared resources during concurrent execution. A remote attacker can exploit this by enticing a user to visit a malicious HTML page, potentially leading to arbitrary code execution within the renderer process sandbox. The issue was addressed in Chrome version 151.0.7922.72. Chromium developers have classified this with a 'Low' security severity.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date