Description
Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-18
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A type confusion bug in V8, the JavaScript engine used by Chrome, allows a remote attacker to craft an HTML page that triggers arbitrary code execution within the browser sandbox. The fault enables the attacker to run code that was never intended to execute, effectively breaching the sandbox's isolation guarantees.

Affected Systems

Google Chrome users affected are those running V8 versions prior to 151.0.7922.169. The vulnerability is tied to the Chrome browser itself, regardless of operating system, and impacts any user who visits a maliciously constructed web page.

Risk and Exploitability

Chromium classifies the flaw as high severity, and while the EPSS score is not available, the lack of KEV listing does not diminish the risk. The attack vector is likely an out‑of‑band crafted HTML page served over the web. If an attacker can lure a user into loading the page, arbitrary code will run inside the sandbox, possibly leading to privilege escalation or data exfiltration on the target machine.

Generated by OpenCVE AI on August 18, 2026 at 21:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 151.0.7922.169 or later through the official update channel.
  • Ensure automatic updates are enabled so that future security patches are applied promptly.
  • If an update cannot be applied immediately, limit exposure by restricting access to untrusted websites or disabling JavaScript via Chrome policy until the vulnerability is patched.

Generated by OpenCVE AI on August 18, 2026 at 21:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Type Confusion Exploitation in Chrome's V8 Engine Enables Remote Code Execution
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 18 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-843
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-18T20:31:28.437Z

Reserved: 2026-08-18T19:45:07.386Z

Link: CVE-2026-76047

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:18:28.863

Modified: 2026-08-18T21:18:28.863

Link: CVE-2026-76047

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T22:00:14Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')