CVE-2026-76043: Incorrect calculation in V8
Chromium: CVE-2026-76043 Incorrect calculation in V8
Other sources
Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.7922.169 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.4129.101
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What does an attacker need to do to exploit this issue?
A user must load a crafted HTML page in an affected Chrome version. Exploitation enables arbitrary code execution inside Chrome’s sandbox, so the attacker’s code is confined by the browser sandbox according to the available information.
Which Chrome versions need to be updated?
Google Chrome versions earlier than 151.0.7922.169 are affected. Updating Chrome to 151.0.7922.169 or later addresses the affected version range stated in the advisory.