Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76043

Опубликовано: 18 авг. 2026
Источник: redhat
CVSS3: 8.8

Описание

Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

A flaw was found in the V8 component of Google Chrome. A remote attacker could exploit an incorrect calculation vulnerability by enticing a user to visit a specially crafted HTML page. This could lead to arbitrary code execution within the browser's sandbox environment.

Отчет

This is an Important vulnerability in the V8 component of chromium-browser that could lead to arbitrary code execution. Exploitation requires user interaction, where a remote attacker could entice a user to visit a specially crafted HTML page. While the execution is confined to the browser's sandbox, the potential for arbitrary code execution warrants an Important rating.

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2518273chromium-browser: v8: Google Chrome V8: Arbitrary code execution via incorrect calculation in HTML processing

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 1 месяца назад

Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
nvd
около 1 месяца назад

Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

msrc
28 дней назад

Chromium: CVE-2026-76043 Incorrect calculation in V8

CVSS3: 8.8
debian
около 1 месяца назад

Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 a ...

CVSS3: 8.8
github
около 1 месяца назад

Incorrect calculation in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

8.8 High

CVSS3