Google · Google Chrome · CVE-2026-4447
**Name of the Vulnerable Software and Affected Versions**
Google Chrome versions prior to 146.0.7680.153
Microsoft Edge (affected versions not specified)
**Description**
An inappropriate implementation in V8, the JavaScript engine, allows a remote attacker to execute arbitrary code inside a sandbox by using a specially crafted HTML page. This issue is related to deficiencies in the access separation of the isolated environment, specifically involving Maglev Phi untagging.
**Recommendations**
Update to version 146.0.7680.153 or later.