Executive brief
Google Chrome is a widely used web browser. A vulnerability in its V8 JavaScript engine could allow a remote attacker to execute unauthorized code within the browser's security sandbox if a user visits a specially crafted website. While the impact is limited by the sandbox, it could lead to browser crashes or be used as part of a larger attack chain to compromise the user's system.
Technical details
A type confusion vulnerability (CWE-843) exists in the V8 JavaScript engine component of Google Chrome. The flaw occurs when the engine incorrectly handles objects of incompatible types, which can be triggered by a remote attacker through a maliciously crafted HTML page. Successful exploitation allows for arbitrary code execution within the confines of the Chromium renderer sandbox. This vulnerability was addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux. Chromium developers have classified the severity of this specific issue as Low.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed