Executive brief
Google Chrome is a widely used web browser. A vulnerability in its V8 engine could allow a remote attacker to corrupt the browser's memory if a user visits a specially crafted website. This could lead to unauthorized access to information or the ability to modify data within the browser session.
Technical details
A race condition (CWE-362) exists in the V8 JavaScript engine component of Google Chrome. The vulnerability is triggered when the browser processes a specially crafted HTML page, leading to improper synchronization of shared resources. An unauthenticated remote attacker can exploit this flaw to cause heap corruption. Successful exploitation requires user interaction (visiting a malicious site) and has a high attack complexity due to the nature of the race condition. The impact includes potential loss of confidentiality and integrity. The issue is resolved in Chrome version 147.0.7727.55.
Affected products
- Google Chrome versions prior to 147.0.7727.55
Timeline
- 2026-02-26: disclosed: Reported to Chromium by QYmag1c
- 2026-04-07: patched: Chrome 147.0.7727.55 promoted to stable channel
- 2026-04-08: advisory: NVD publication date