Executive brief
Google Chrome's V8 JavaScript engine contained a type confusion vulnerability that could allow an attacker to execute arbitrary code within the browser's sandbox after tricking a user into visiting a malicious webpage. This could lead to data theft, malware installation, or session hijacking on affected systems.
Technical details
A type confusion vulnerability in the V8 JavaScript engine (CVE-2026-78956) allows remote code execution within the Chrome sandbox when a user visits a crafted HTML page. The vulnerability requires social engineering to trick the user into visiting the malicious page; no prior authentication or elevated privileges are required. An attacker can execute arbitrary JavaScript code within the V8 sandbox, potentially accessing sensitive data or establishing a foothold for further exploitation. The vulnerability was patched in Chrome 152.0.7977.65 released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65