Junglewise Threat Intelligence

CVE-2026-6363: Google Chrome type confusion in V8

CVE-2026-6363 · Severity: high · CVSS 8.8 · Published 2026-04-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in the Google Chrome web browser's V8 engine, which is responsible for processing JavaScript. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website. If successful, this could allow the attacker to access sensitive information or potentially execute unauthorized actions on the user's computer.

Technical details

A type confusion vulnerability (CWE-843) exists in the V8 JavaScript engine within Google Chrome. The flaw is triggered when the engine incorrectly handles objects of incompatible types, leading to out-of-bounds memory access. A remote, unauthenticated attacker can exploit this by enticing a user to load a malicious HTML page. This can result in memory corruption, potentially leading to arbitrary code execution or information disclosure. The issue is resolved in Chrome version 147.0.7727.101 and later.

Affected products

  • Google Chrome prior to 147.0.7727.101

Timeline

  • 2026-03-24: disclosed: Reported by Google researchers
  • 2026-04-15: patched: Fixed in version 147.0.7727.101/102
  • 2026-04-15: advisory

References

Related threats