CVE-2026-79236
8.8Google · Chrome
A type confusion vulnerability in the V8 engine of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
Executive summary
Google Chrome versions prior to 152.0.7977.65 are susceptible to a high-severity type confusion flaw in the V8 engine that enables remote code execution.
Vulnerability
This vulnerability is a type confusion flaw (CWE-843) within the V8 JavaScript engine. An unauthenticated remote attacker can trigger this by enticing a user to visit a specially crafted HTML page, leading to arbitrary code execution within the browser sandbox.
Business impact
Successful exploitation of this vulnerability permits a remote attacker to execute arbitrary code on the host machine. Given the CVSS score of 8.8, this poses a significant risk of system compromise, potential data exfiltration, and unauthorized access to user sessions, all of which could result in severe reputational and operational damage to the organization.
Remediation
Immediate Action: Update Google Chrome to version 152.0.7977.65 or later immediately to apply the vendor-provided security patches.
Proactive Monitoring: Review enterprise endpoint logs for unusual browser activity or unexpected process spawns originating from the Chrome application.
Compensating Controls: Deploy endpoint protection solutions that monitor for suspicious memory access patterns or unauthorized attempts to execute code within browser processes.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The severity of this vulnerability, combined with its potential for remote code execution, necessitates prompt action. Administrators should prioritize the deployment of the latest Chrome security updates across all managed workstations to ensure the V8 engine is hardened against this type confusion attack.