Executive brief
Google Chrome is a widely used web browser. A security vulnerability in its V8 JavaScript engine could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized data access or further system compromise.
Technical details
A type confusion vulnerability (CWE-843) exists in the V8 JavaScript engine within Google Chrome. The flaw is triggered when the engine incorrectly processes objects of incompatible types, which can be exploited by a remote attacker through a specially crafted HTML page. Successful exploitation allows for arbitrary code execution within the context of the Chromium sandbox. The vulnerability was addressed in Chrome version 147.0.7727.138 for Windows, Mac, and Linux. User interaction is required as a victim must navigate to a malicious URL.
Affected products
- Google Chrome prior to 147.0.7727.138
Timeline
- 2026-04-09: disclosed: Reported by external researcher q@calif.io
- 2026-04-28: patched: Fixed in Chrome Stable Channel update 147.0.7727.138
- 2026-04-28: advisory