ZeroHour

CVE-2026-82072

mass

Out-of-Bounds Read in Chrome's V8 Enables Sandbox-Confined Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p21
Published
()
Modified
AI analysis

Google Chrome versions prior to 151.0.7922.72 contain an out-of-bounds read (CWE-125) in the V8 JavaScript engine. An attacker can trigger the flaw by convincing a user to open a crafted HTML page, with user interaction required per the CVSS vector. Successful exploitation allows the attacker to execute arbitrary code inside the browser's renderer sandbox, confining the impact to the sandboxed process rather than the full system. All users of affected Chrome builds are exposed; notably, Chromium's security team rated the issue Medium even though the CVSS 3.1 vector scores 8.8 (High). No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is currently known, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Update Google Chrome to version 151.0.7922.72 or later and verify the installed version at chrome://settings/help or via enterprise update management. As an interim mitigation, exercise caution when opening untrusted websites, and confirm that no managed endpoints remain on pre-151.0.7922.72 builds. Users of other Chromium-based browsers should watch for equivalent V8 fixes from their respective vendors.

Affected
Google Chromeall versions prior to 151.0.7922.72
Estimated exposure
massbillions of potential installs (Chrome's global user base), with the vulnerable subset shrinking rapidly as auto-update delivers 151.0.7922.72 — Chrome's worldwide installed base runs to billions of users with roughly 60% browser market share, but Chrome's aggressive auto-update mechanism means only a diminishing fraction remains on pre-151.0.7922.72 builds shortly after the fix…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.