Description
Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Stack buffer overflow in the V8 JavaScript engine of Google Chrome prior to version 150.0.7871.182 allows a remote attacker to execute arbitrary code inside the browser sandbox. The flaw, a classic stack buffer overflow, can be triggered by a specially crafted HTML page, giving the attacker the ability to run code with the privileges of the browser process.

Affected Systems

The vulnerability affects Google Chrome on all desktop platforms that are running a stable channel build earlier than 150.0.7871.182 on Windows, macOS, or Linux; users of these versions may be exposed if they visit malicious or compromised web pages.

Risk and Exploitability

The EPSS score is below 1 % and the flaw is not listed in CISA’s KEV catalog, which indicates a low probability of widespread exploitation at the time of this analysis. Nonetheless, the CVSS score of 8.8 and the ability to execute arbitrary code in the browser sandbox give this vulnerability a high severity rating. The likely attack vector is a remote attacker hosting a malicious web page that serves a crafted HTML payload; a victim visiting that page could trigger the buffer overflow from the client side.

Generated by OpenCVE AI on August 4, 2026 at 00:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.182 or later, which contains the V8 bug fix.
  • Ensure that future mitigation releases are applied promptly.
  • If an upgrade cannot be performed immediately, limit exposure by disabling JavaScript for unknown sites and using a reputable security extension that blocks malicious content.

Generated by OpenCVE AI on August 4, 2026 at 00:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4701-1 chromium security update
Debian DSA Debian DSA DSA-6396-1 chromium security update
History

Tue, 04 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Stack Buffer Overflow in V8 Engine Enables Remote Code Execution from Crafted Web Page

Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via V8 Stack Buffer Overflow in Chrome

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via V8 Stack Buffer Overflow in Chrome

Wed, 22 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 21 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-121
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-24T12:51:52.103Z

Reserved: 2026-07-20T22:23:06.041Z

Link: CVE-2026-16418

cve-icon Vulnrichment

Updated: 2026-07-24T12:51:46.458Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:30:18Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow