CVE-2026-82072

8.8

Google · Chrome

An out of bounds read vulnerability in the V8 engine of Google Chrome allows a remote attacker to execute arbitrary code within the sandbox via a crafted HTML page.

Executive summary

A critical out of bounds read vulnerability in Google Chrome allows remote attackers to achieve arbitrary code execution through malicious web content.

Vulnerability

This vulnerability involves an out of bounds read within the V8 JavaScript engine. An unauthenticated remote attacker can trigger this flaw by enticing a user to navigate to a specifically crafted HTML page, potentially leading to arbitrary code execution within the browser sandbox.

Business impact

The ability for a remote attacker to execute arbitrary code within the browser sandbox poses a significant risk to organizational security. Successful exploitation could lead to full compromise of the local browser environment, potentially facilitating data theft, session hijacking, or the deployment of further malicious payloads. Given the CVSS score of 8.8, this vulnerability represents a high risk that requires immediate attention to protect internal workstations and sensitive corporate data.

Remediation

Immediate Action: Update all Google Chrome instances to version 151.0.7922.72 or later immediately to incorporate the necessary security patches.

Proactive Monitoring: Monitor endpoint security logs for unusual browser activity or unexpected child process spawning originating from the Google Chrome application.

Compensating Controls: Deploy browser isolation solutions or configure group policies to restrict the execution of untrusted scripts and content, which can help mitigate the impact of browser-based exploits.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit available in our curated sources.

Analyst recommendation

Organizations should prioritize the deployment of the Google Chrome update across all managed devices. Because browser vulnerabilities are a common target for remote attackers, failure to patch may expose users to drive-by download attacks. Ensure that all systems are updated to version 151.0.7922.72 or higher as soon as possible to neutralize this threat.

More Google CVEs

Sources