Description
Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-18
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an incorrect calculation inside the V8 JavaScript engine in Google Chrome versions prior to 151.0.7922.169. A crafted HTML page sent to the victim can trigger the calculation bug and cause the sandbox to be bypassed, allowing the attacker to execute arbitrary code with the privileges of the browser. This is a direct remote code execution vulnerability classified as CWE-682.

Affected Systems

Google Chrome browsers on all platforms using the V8 engine and running any stable channel version older than 151.0.7922.169 are affected. The issue is limited to Chrome’s normal operation when processing HTML content; no additional components are mentioned.

Risk and Exploitability

The vulnerability is high severity and, although no EPSS score is available, the lack of a KEV listing does not diminish the risk. The likely attack vector is a web page that a user visits or that loads in a web‑based application. Exploitation requires no privileged interaction beyond normal browsing; any user who opens a maliciously crafted page could be compromised.

Generated by OpenCVE AI on August 18, 2026 at 21:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 151.0.7922.169 or newer via the built‑in updater.
  • If the automatic updater is disabled, manually download and install the latest Chrome revision from the official site.
  • Verify that the Chrome sandbox is enabled (default) and avoid executing scripts from untrusted origins; consider applying a content security policy that restricts inline scripts.

Generated by OpenCVE AI on August 18, 2026 at 21:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 18 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution in Chrome V8 Engine via Malformed HTML

Tue, 18 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-682
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-18T20:31:27.736Z

Reserved: 2026-08-18T19:44:59.067Z

Link: CVE-2026-76043

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:18:28.407

Modified: 2026-08-18T21:18:28.407

Link: CVE-2026-76043

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T22:30:04Z

Weaknesses