ZeroHour

CVE-2026-84326

mass

Uninitialized Resource in Chrome's V8 Engine Allows Sandbox-Confined Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p20
Published
()
Modified
AI analysis

CVE-2026-84326 is an uninitialized resource flaw (CWE-908) in the V8 JavaScript/WebAssembly engine of Google Chrome, rated High by Chromium security. A remote attacker can trigger it by luring a user to a specially crafted HTML page, where the uninitialized memory in V8 can be leveraged for arbitrary code execution. The attacker gains the ability to run code inside the Chrome renderer sandbox, which constrains the compromise to the browser's sandboxed process rather than the underlying operating system. All users of Google Chrome versions prior to 152.0.7977.75 are affected. As of now there is no known public proof-of-concept, no entry in the CISA KEV catalog, and a modest EPSS score of 0.3%, indicating no confirmed exploitation in the wild.

What to do: Update Google Chrome to 152.0.7977.75 or later and confirm the running version via chrome://version. Organizations should push the patched build through their update management channels and remind users that Chromium-based browsers derived from V8 should receive equivalent fixes from their respective vendors; given the lack of known exploitation, standard patch-cycle urgency is appropriate, though V8 memory-safety bugs are routinely targeted by exploit chains once disclosed.

Affected
Google ChromeAll versions prior to 152.0.7977.75
Estimated exposure
massOn the order of billions of Chrome installations (Chrome holds roughly two-thirds of global desktop browser share and billions of active users; every instance… — Chrome is the world's dominant browser with an estimated 60-70% desktop market share and billions of active installations, so essentially the entire installed base of Chrome users on unpatched versions is potentially exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-908
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.