Executive brief
Google Chrome's V8 JavaScript engine contains a type confusion vulnerability that could allow an attacker to read memory from inside the browser's sandbox. An attacker could exploit this by tricking a user into visiting a malicious webpage, potentially exposing sensitive data or enabling further attacks on the user's system.
Technical details
This vulnerability is a type confusion flaw in V8, Chrome's JavaScript engine, affecting versions prior to 152.0.7977.65. The vulnerability allows a remote attacker to read memory inside the sandbox via a crafted HTML page, requiring user interaction (social engineering) to visit a malicious site. Type confusion occurs when code incorrectly assumes the type of a variable or object, allowing attackers to access or manipulate memory in unintended ways. The vulnerability is fixed in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-79045 disclosed in Chrome 152 release notes
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65