Junglewise Threat Intelligence

CVE-2026-7337: Google Chrome type confusion in V8

CVE-2026-7337 · Severity: high · CVSS 8.8 · Published 2026-04-28

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its V8 JavaScript engine could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized data access or further system compromise.

Technical details

A type confusion vulnerability (CWE-843) exists in the V8 JavaScript engine within Google Chrome. The flaw is triggered when the engine incorrectly processes objects of incompatible types, which can be exploited by a remote attacker through a specially crafted HTML page. Successful exploitation allows for arbitrary code execution within the context of the Chromium sandbox. The vulnerability was addressed in Chrome version 147.0.7727.138 for Windows, Mac, and Linux. User interaction is required as a victim must navigate to a malicious URL.

Affected products

  • Google Chrome prior to 147.0.7727.138

Timeline

  • 2026-04-09: disclosed: Reported by external researcher q@calif.io
  • 2026-04-28: patched: Fixed in Chrome Stable Channel update 147.0.7727.138
  • 2026-04-28: advisory

References

Related threats