CVE-2026-84326
massUninitialized Resource in Chrome's V8 Engine Allows Sandbox-Confined Code Execution
CVE-2026-84326 is an uninitialized resource flaw (CWE-908) in the V8 JavaScript/WebAssembly engine of Google Chrome, rated High by Chromium security. A remote attacker can trigger it by luring a user to a specially crafted HTML page, where the uninitialized memory in V8 can be leveraged for arbitrary code execution. The attacker gains the ability to run code inside the Chrome renderer sandbox, which constrains the compromise to the browser's sandboxed process rather than the underlying operating system. All users of Google Chrome versions prior to 152.0.7977.75 are affected. As of now there is no known public proof-of-concept, no entry in the CISA KEV catalog, and a modest EPSS score of 0.3%, indicating no confirmed exploitation in the wild.
What to do: Update Google Chrome to 152.0.7977.75 or later and confirm the running version via chrome://version. Organizations should push the patched build through their update management channels and remind users that Chromium-based browsers derived from V8 should receive equivalent fixes from their respective vendors; given the lack of known exploitation, standard patch-cycle urgency is appropriate, though V8 memory-safety bugs are routinely targeted by exploit chains once disclosed.
| Google Chrome | All versions prior to 152.0.7977.75 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-908
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.