Executive brief
A vulnerability in Google Chrome's V8 engine could allow a remote attacker to execute unauthorized code on a user's computer. This occurs when a user visits a specially crafted website, potentially leading to the compromise of the browser's security sandbox. Successful exploitation could allow an attacker to disrupt operations or access sensitive information within the browser environment.
Technical details
A type confusion vulnerability (CWE-843) exists in the V8 JavaScript engine component of Google Chrome. The flaw is triggered when the engine incorrectly handles objects of incompatible types during execution. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to achieve arbitrary code execution within the browser's sandbox environment. Google has addressed this issue in Chrome version 148.0.7778.168 for Windows, Mac, and Linux.
Affected products
- Google Chrome Prior to 148.0.7778.168
Timeline
- 2026-03-26: disclosed: Reported by Google internal researchers
- 2026-05-12: patched: Fixed in Chrome version 148.0.7778.168
- 2026-05-14: advisory: NVD publication date