CVE-2026-79045
8.8Google · Chrome
A type confusion vulnerability in the V8 engine of Google Chrome allows remote attackers to read memory within the sandbox via a crafted HTML page.
Executive summary
A high-severity type confusion vulnerability in Google Chrome's V8 engine could allow a remote attacker to compromise sensitive memory data through social engineering.
Vulnerability
This is a type confusion flaw (CWE-843) located in the V8 JavaScript engine, which can be triggered by an unauthenticated remote attacker who successfully lures a user to visit a malicious HTML page.
Business impact
Successful exploitation of this vulnerability permits unauthorized reading of memory within the browser sandbox, which may lead to the exposure of sensitive information. With a CVSS score of 8.8, the vulnerability poses a significant risk to data confidentiality and integrity, potentially facilitating further attacks against the host environment.
Remediation
Immediate Action: Update all Google Chrome installations to version 152.0.7977.65 or later immediately to apply the vendor-provided patch.
Proactive Monitoring: Monitor network traffic for unusual patterns associated with browser-based requests and review endpoint logs for crashes related to the V8 engine.
Compensating Controls: Deploy endpoint protection solutions that detect malicious browser activity and ensure users are trained to recognize and avoid untrusted or suspicious web links.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit available in the provided data.
Analyst recommendation
Given the critical nature of browser security and the potential for memory disclosure, organizations must prioritize updating all instances of Google Chrome. Administrators should leverage centralized management tools to ensure the latest stable version is deployed across the enterprise to mitigate this risk.