Junglewise Threat Intelligence

CVE-2026-7902: Out of bounds memory access in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandb

CVE-2026-7902 · Severity: high · CVSS 8.8 · Published 2026-05-06

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its V8 JavaScript engine could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is initially confined to the browser's security sandbox, it represents a significant risk to data privacy and system integrity if combined with other flaws.

Technical details

An out-of-bounds memory access vulnerability exists in the V8 JavaScript engine within Google Chrome. The flaw is triggered when the engine processes a specially crafted HTML page, leading to memory corruption. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, potentially achieving arbitrary code execution within the browser's sandbox environment. The vulnerability is addressed in Google Chrome version 148.0.7778.96 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 148.0.7778.96

Timeline

  • 2026-04-13: disclosed: Reported by JunYoung Park of KAIST Hacking Lab
  • 2026-05-05: patched: Fixed in Chrome 148.0.7778.96 stable channel update
  • 2026-05-06: advisory: NVD publication date

References

Related threats