Junglewise Threat Intelligence

CVE-2026-78910: Google Chrome buffer overflow in V8

CVE-2026-78910 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's V8 JavaScript engine contains a buffer overflow vulnerability that allows attackers to execute arbitrary code within the browser's security sandbox by viewing a crafted web page. While the attack is contained within the sandbox, an attacker with sandbox escape capabilities could gain full control of the affected system. This vulnerability affects millions of Chrome users on Windows, Mac, and Linux.

Technical details

A buffer overflow exists in the V8 JavaScript engine shipped with Google Chrome versions prior to 152.0.7977.65. The vulnerability allows a remote attacker to trigger out-of-bounds memory writes by crafting malicious JavaScript code delivered via a web page. The attack requires only that a user visit a malicious website—no authentication or additional interaction is required beyond standard browsing. Successful exploitation enables arbitrary code execution within the browser sandbox. The patch is available in Chrome 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: CVE-2026-78910 published; Chrome 152.0.7977.65 released with fix
  • 2026-08-25: patched: Patch available in Chrome 152.0.7977.65 for Windows, Mac, and Linux

References

Related threats