CVE-2026-76038: Type confusion in V8
Chromium: CVE-2026-76038 Type confusion in V8
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
— NVD
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.7922.169 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.4129.101 - Upgrade
Upgrade
Chromium-based (Google Chrome / Microsoft Edge Chromium-based) - V8to a version that resolves this vulnerability.Fixed in 151.0.7922.169
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
Which Chrome installations need to be updated?
Systems running Google Chrome versions earlier than 151.0.7922.169 are affected. Updating Chrome to 151.0.7922.169 or later addresses the vulnerable version range described.
What does exploitation require and what access could it provide?
An attacker would need to induce a user to load a crafted HTML page remotely. Successful exploitation can execute arbitrary code inside Chrome's sandbox.