Description
Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-01
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an integer overflow in the V8 JavaScript engine, catalogued as CWE‑472, that allows a crafted HTML page to trigger buffer overrun. When this overflow occurs, the attacker can execute arbitrary code inside the browser’s sandbox, potentially enabling the execution of native operating‑system code that bypasses the sandbox. This flaw provides a high‑severity attack surface but does not specify known public exploits.

Affected Systems

All installations of Google Chrome built before version 150.0.7871.46 are affected. The vulnerability exists in every platform where Chrome’s V8 engine is present, covering Windows, macOS, Linux, and Android.

Risk and Exploitability

The CVSS score of 8.8 underscores a serious risk, while the EPSS score of less than 1% indicates that exploitation attempts are currently rare. Based on the description, it is inferred that an attacker must deliver a malicious HTML page that the victim opens in Chrome, a common user action. Once the overflow is triggered, arbitrary code runs within the sandboxed environment, potentially escalating privileges to the host operating system if the sandbox is broken.

Generated by OpenCVE AI on July 17, 2026 at 11:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Chrome version 150.0.7871.46 or later from the official update channel.
  • If an upgrade cannot be performed immediately, disable JavaScript globally or use a trusted extension that prevents V8 execution until the patch is applied.
  • Maintain the operating system and other software at their latest security patches to minimize secondary compromise if exploitation succeeds.

Generated by OpenCVE AI on July 17, 2026 at 11:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title V8 Integer Overflow Enables Remote Code Execution via Crafted HTML in Chrome

Thu, 16 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title V8 Integer Overflow Exploitable for Remote Code Execution in Chrome

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title V8 Integer Overflow Exploitable for Remote Code Execution in Chrome

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title V8 Integer Overflow Leading to Remote Code Execution in Chrome

Wed, 08 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title V8 Integer Overflow Leading to Remote Code Execution in Chrome

Tue, 07 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in V8 Allows Remote Code Execution in Chrome before 150.0.7871.46

Tue, 07 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in V8 Allows Remote Code Execution in Chrome before 150.0.7871.46

Mon, 06 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow in V8 Enables Remote Code Execution in Chrome

Sun, 05 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow in V8 Enables Remote Code Execution in Chrome

Sun, 05 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title V8 Integer Overflow Allows Remote Code Execution via Malicious HTML in Chrome

Sat, 04 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title V8 Integer Overflow Allows Remote Code Execution via Malicious HTML in Chrome

Sat, 04 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title V8 Integer Overflow in Chrome Enables Remote Code Execution

Fri, 03 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title V8 Integer Overflow in Chrome Enables Remote Code Execution

Thu, 02 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in V8 Allows Remote Code Execution in Chrome

Thu, 02 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in V8 Allows Remote Code Execution in Chrome

Thu, 02 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 02 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-472
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-03T03:55:49.325Z

Reserved: 2026-07-01T21:37:35.425Z

Link: CVE-2026-14430

cve-icon Vulnrichment

Updated: 2026-07-02T00:16:00.411Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T12:00:04Z

Weaknesses
  • CWE-472

    External Control of Assumed-Immutable Web Parameter