Executive brief
Google Chrome is a widely used web browser. A vulnerability in its V8 JavaScript engine could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited to the browser's security sandbox, it represents a significant risk to system integrity and user data.
Technical details
An out-of-bounds (OOB) write vulnerability (CWE-787) exists in the V8 JavaScript engine within Google Chrome. The flaw is triggered when the engine processes a specially crafted HTML page, allowing a remote, unauthenticated attacker to perform memory corruption. Successful exploitation enables arbitrary code execution within the Chromium renderer sandbox. The issue was addressed in Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop
- 2026-05-28: disclosed: NVD publication date