Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76038

Опубликовано: 18 авг. 2026
Источник: redhat
CVSS3: 8.8

Описание

Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

A flaw was found in V8, the open-source JavaScript engine used in Google Chrome. This type confusion vulnerability allows a remote attacker to execute arbitrary code within the browser's security sandbox. Exploitation occurs when a user visits a specially crafted HTML page, leading to potential compromise of the affected system.

Отчет

This vulnerability is rated as Important. A type confusion flaw in the V8 JavaScript engine can lead to remote code execution when processing a specially crafted HTML page. Exploitation requires user interaction, as an attacker must entice a user to visit a malicious website. This primarily impacts desktop environments and applications that render untrusted web content, such as Chromium and applications embedding QtWebEngine.

Меры по смягчению последствий

To mitigate this vulnerability, users should avoid opening untrusted web content or visiting untrusted websites. For systems where web browsing functionality is not required, consider removing packages that provide web rendering capabilities, such as chromium or qt5-qtwebengine/qt6-qtwebengine. Note that removing these packages may impact the functionality of other desktop applications or the desktop environment itself.

Дополнительная информация

Статус:

Important
Дефект:
CWE-843
https://bugzilla.redhat.com/show_bug.cgi?id=2518262chromium-browser: v8: V8: Remote code execution via type confusion in crafted HTML.

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 1 месяца назад

Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
nvd
около 1 месяца назад

Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

msrc
28 дней назад

Chromium: CVE-2026-76038 Type confusion in V8

CVSS3: 8.8
debian
около 1 месяца назад

Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed ...

CVSS3: 8.8
github
около 1 месяца назад

Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

8.8 High

CVSS3