Chromium V8 type confusion

A type-confusion condition in V8 may allow crafted web content to violate browser process memory safety.

Published 31 Aug 2026Updated 1 Sep 20269 sources
CVSS 8.1

What happened

An incorrect object type assumption in V8 can lead to unsafe memory access when processing specially formed JavaScript.

Affected versions

Chromium: 138.0.7204.0 Fixed: 138.0.7204.12.

Why it matters

Browsers process untrusted content continuously, making memory-safety defects relevant even when additional containment must be bypassed.

Detection & mitigation

  • Update Chromium-based browsers to the latest stable release.
  • Confirm managed browser fleets apply automatic updates.
  • Monitor vendor advisories for revised affected-version ranges.

Public PoC references

No public PoC reference has passed the current publication threshold.