Executive brief
Google Chrome is a widely used web browser. A vulnerability in its V8 JavaScript engine could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is initially confined to the browser's security sandbox, it represents a significant risk to data privacy and system integrity if combined with other flaws.
Technical details
An out-of-bounds memory access vulnerability exists in the V8 JavaScript engine within Google Chrome. The flaw is triggered when the engine processes a specially crafted HTML page, leading to memory corruption. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, potentially achieving arbitrary code execution within the browser's sandbox environment. The vulnerability is addressed in Google Chrome version 148.0.7778.96 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 148.0.7778.96
Timeline
- 2026-04-13: disclosed: Reported by JunYoung Park of KAIST Hacking Lab
- 2026-05-05: patched: Fixed in Chrome 148.0.7778.96 stable channel update
- 2026-05-06: advisory: NVD publication date