CVE-2026-76047: Type confusion in V8
Chromium: CVE-2026-76047 Type confusion in V8
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
— NVD
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.7922.169 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.4129.101 - Upgrade
Upgrade
Google Chrome / Chromium V8to a version that resolves this vulnerability.Fixed in 151.0.7922.169
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
Which Chrome installations are exposed?
Users of Google Chrome versions earlier than 151.0.7922.169 are affected when they load an attacker-crafted HTML page. The issue enables arbitrary code execution inside Chrome's sandbox.
What does an attacker need to exploit this issue?
An attacker needs to cause the target to load a crafted HTML page. The provided information does not indicate that authentication, local access, or additional user interaction is required beyond visiting or rendering that page.
What should teams do to remediate the vulnerability?
Update Google Chrome to version 151.0.7922.169 or later. No alternative mitigation is provided in the available information.