Junglewise Threat Intelligence

CVE-2026-8540: Google Chrome Type Confusion in V8

CVE-2026-8540 · Severity: high · CVSS 8.8 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's V8 engine could allow a remote attacker to execute unauthorized code on a user's computer. This occurs when a user visits a specially crafted website, potentially leading to the compromise of the browser's security sandbox. Successful exploitation could allow an attacker to disrupt operations or access sensitive information within the browser environment.

Technical details

A type confusion vulnerability (CWE-843) exists in the V8 JavaScript engine component of Google Chrome. The flaw is triggered when the engine incorrectly handles objects of incompatible types during execution. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to achieve arbitrary code execution within the browser's sandbox environment. Google has addressed this issue in Chrome version 148.0.7778.168 for Windows, Mac, and Linux.

Affected products

  • Google Chrome Prior to 148.0.7778.168

Timeline

  • 2026-03-26: disclosed: Reported by Google internal researchers
  • 2026-05-12: patched: Fixed in Chrome version 148.0.7778.168
  • 2026-05-14: advisory: NVD publication date

References

Related threats