PT-2026-26518 · Google+1 · Google Chrome+1
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 146.0.7680.153
Microsoft Edge (affected versions not specified)
Description
An inappropriate implementation in V8, the JavaScript engine, allows a remote attacker to execute arbitrary code inside a sandbox by using a specially crafted HTML page. This issue is related to deficiencies in the access separation of the isolated environment, specifically involving Maglev Phi untagging.
Recommendations
Update to version 146.0.7680.153 or later.
Fix
DoS
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Google Chrome
Red Os