Executive brief
Google Chrome's V8 JavaScript engine contains an uninitialized resource vulnerability that allows remote attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a specially crafted website. Successful exploitation could lead to unauthorized code execution and potential compromise of user data or system access, though the sandbox mitigates full system compromise.
Technical details
An uninitialized resource flaw in V8 (Google's JavaScript engine) in Chrome versions prior to 152.0.7977.75 allows remote code execution within the browser sandbox. The vulnerability is triggered via a crafted HTML page delivered over the network; no authentication or local access is required, but user interaction (visiting the malicious page) is necessary. An attacker can achieve arbitrary code execution within the sandboxed V8 process, potentially leading to information disclosure or further exploitation chains. The vulnerability has been patched in Chrome 152.0.7977.75 and later releases.
Affected products
- Google Chrome prior to 152.0.7977.75
Timeline
- 2026-09-02: disclosed