Junglewise Threat Intelligence

CVE-2026-79236: Google Chrome type confusion in V8

CVE-2026-79236 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's V8 JavaScript engine contains a type confusion vulnerability that could allow an attacker to execute arbitrary code with sandboxed privileges by tricking a user into visiting a malicious webpage. This could lead to compromise of the browser process and potential access to sensitive user data stored in the browser.

Technical details

Type confusion in V8, Google Chrome's JavaScript engine, allows remote code execution within the browser sandbox via a crafted HTML page. The vulnerability exists in versions prior to 152.0.7977.65 and is triggered by processing malformed JavaScript code that confuses the engine's type system. An attacker must convince a user to visit a malicious website to exploit this flaw; no authentication or user action beyond visiting the page is required. Successful exploitation results in arbitrary code execution within the V8 sandbox context. The vulnerability was patched in Chrome 152.0.7977.65 and later releases.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats