Description
Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-04-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Out‑of‑bounds memory access potentially leading to remote exploitation
Action: Immediate Patch
AI Analysis

Impact

V8, the JavaScript engine embedded in Google Chrome, suffered a type‑confusion flaw that permitted a maliciously crafted HTML page to trigger a memory corruption error. The vulnerability can lead to out‑of‑bounds memory access, which in turn could allow an attacker to influence program execution or leak sensitive data. The weakness is a classic type‑confusion issue (CWE‑843) and the official severity assigned by Chromium is medium.

Affected Systems

The flaw is present in all versions of Google Chrome before 147.0.7727.101. This includes the stable channel builds shipped to end users, enterprise deployments, and any systems that have not upgraded to the patched release. Any device running an affected Chrome version that processes untrusted Web content is potentially exposed.

Risk and Exploitability

The CVSS score is 8.8, indicating high severity, reflecting the need for a crafted input delivered over the network but with no known active exploitation. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog, suggesting that publicly disclosed exploitation is not yet widespread. Nevertheless, the attack vector is remote and can be carried out through a single malicious HTML page. The risk is therefore high, with the primary mitigation being the application of the patch that appears in the quoted release notes.

Generated by OpenCVE AI on April 15, 2026 at 21:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 147.0.7727.101 or later via the standard update mechanism.
  • Where automatic updates are disabled, install the latest installer directly from Google’s official site or deploy the update through enterprise management tools.
  • For environments that cannot upgrade immediately, restrict execution of untrusted JavaScript by implementing a restrictive Content Security Policy and disabling inline scripts in the browser configuration.

Generated by OpenCVE AI on April 15, 2026 at 21:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
Title V8 Type Confusion Leading to Out‑of‑Bounds Memory Access via Malicious HTML Page V8: Google Chrome: Chromium: Google Chrome V8: Out-of-bounds memory access via crafted HTML page
References
Metrics threat_severity

None

threat_severity

Important


Wed, 15 Apr 2026 22:15:00 +0000

Type Values Removed Values Added
Title V8 Type Confusion Leading to Out‑of‑Bounds Memory Access via Malicious HTML Page

Wed, 15 Apr 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 15 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Description Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-843
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-16T03:55:45.999Z

Reserved: 2026-04-15T14:28:38.485Z

Link: CVE-2026-6363

cve-icon Vulnrichment

Updated: 2026-04-15T19:38:53.048Z

cve-icon NVD

Status : Received

Published: 2026-04-15T20:16:43.690

Modified: 2026-04-15T20:16:43.690

Link: CVE-2026-6363

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-15T19:04:57Z

Links: CVE-2026-6363 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T22:00:06Z

Weaknesses