Executive brief
Google Chrome is a widely used web browser. A security vulnerability in its V8 JavaScript engine could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized actions or serve as a stepping stone for further system compromise.
Technical details
A type confusion vulnerability (CWE-843) exists in the V8 JavaScript engine component of Google Chrome. The flaw is triggered when the engine incorrectly interprets the type of a resource, leading to memory corruption. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious HTML page. Successful exploitation allows for arbitrary code execution within the Chromium sandbox. The vulnerability is addressed in Chrome version 147.0.7727.55 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-03-12: disclosed: Reported by Project WhatForLunch (@pjwhatforlunch)
- 2026-04-07: patched: Chrome 147.0.7727.55 released to stable channel
- 2026-04-08: advisory: NVD publication date