Junglewise Threat Intelligence

CVE-2026-78938: Google Chrome type confusion in V8 engine

CVE-2026-78938 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's V8 JavaScript engine contains a type confusion vulnerability that allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious website. This vulnerability affects millions of Chrome users and could enable attackers to compromise user data, inject malware, or hijack browser functionality on vulnerable systems.

Technical details

A type confusion flaw exists in the V8 JavaScript engine (Chrome's core component) that allows remote code execution within the sandbox through a crafted HTML page. The vulnerability requires user interaction (visiting a malicious page) but does not require authentication or elevated privileges. An attacker can exploit this to execute arbitrary code within the browser's sandbox context, potentially breaking out of sandbox isolation and compromising the underlying system. The fix is available in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats