Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-17948

CVE-2026-17948: Google Chrome V8 RCE Vulnerability

CVE-2026-17948 is a type confusion RCE vulnerability in V8 engine within Google Chrome that enables arbitrary code execution via malicious extensions. This article covers technical details, affected versions, and mitigations.

Published:

CVE-2026-17948 Overview

CVE-2026-17948 is a type confusion vulnerability in the V8 JavaScript engine used by Google Chrome versions prior to 151.0.7922.72. An attacker who convinces a user to install a malicious Chrome extension can execute arbitrary code inside the Chrome sandbox by delivering a crafted extension. Chromium rates the security severity as Low because exploitation requires user interaction to install an attacker-controlled extension, and code execution remains confined to the renderer sandbox. The flaw is tracked under CWE-843: Access of Resource Using Incompatible Type.

Critical Impact

Successful exploitation allows arbitrary code execution within the Chrome renderer sandbox via a malicious extension, providing a foothold for further attacks against the browser process.

Affected Products

  • Google Chrome for Desktop prior to 151.0.7922.72
  • Chromium-based browsers embedding the affected V8 build
  • Extensions ecosystem targeting the V8 engine in vulnerable Chrome releases

Discovery Timeline

  • 2026-07-30 - CVE-2026-17948 published to NVD
  • 2026-07-30 - Last updated in NVD database
  • Fix shipped in the Chrome Stable channel update referenced in the Google Chrome Stable Update

Technical Details for CVE-2026-17948

Vulnerability Analysis

The vulnerability is a type confusion condition in V8, Chrome's JavaScript and WebAssembly engine. Type confusion occurs when code operates on an object assuming one type while the underlying memory represents another. In V8, this typically undermines hidden class and map assumptions used during just-in-time (JIT) compilation and inline caching, enabling attacker-controlled reads and writes against engine-managed memory.

Because the flaw is reachable through a crafted Chrome Extension, the attack surface differs from a drive-by web-content exploit. An extension executes with elevated privileges inside its own renderer and can invoke extension APIs, load arbitrary scripts, and stage payloads that exercise the vulnerable V8 code path reliably. The result is arbitrary code execution within the sandboxed renderer process. Additional details are tracked in the Chromium Issue Tracker #516849257.

Root Cause

The root cause is improper type checking in V8, classified as [CWE-843]. Object type assumptions are not consistently validated before the engine dereferences or operates on the object, allowing a crafted script to coerce V8 into treating memory as an incompatible type.

Attack Vector

Exploitation requires the victim to install a malicious extension distributed by the attacker. Once installed, the extension triggers the vulnerable V8 code path with crafted JavaScript to achieve arbitrary code execution inside the sandbox. No unauthenticated network attack path exists; social engineering or supply-chain compromise of an existing extension is the practical delivery mechanism.

No verified public proof-of-concept code is available for this issue. Refer to the Chromium Issue Tracker #516849257 for technical details once Google unrestricts the report.

Detection Methods for CVE-2026-17948

Indicators of Compromise

  • Chrome browser versions reporting chrome://version below 151.0.7922.72 on managed endpoints
  • Newly installed or side-loaded Chrome extensions from outside the Chrome Web Store, particularly those requesting broad scripting, tabs, or <all_urls> host permissions
  • Renderer process crashes referencing V8 or unexpected child process spawns from chrome.exe

Detection Strategies

  • Inventory installed Chrome extensions across the fleet and flag unsigned, developer-mode, or recently published extensions with elevated permissions
  • Alert on Chrome browser telemetry indicating renderer crashes tied to V8 JIT or unexpected native code execution originating from an extension context
  • Correlate outbound network activity from Chrome renderers with extension IDs to identify command-and-control patterns following extension installation

Monitoring Recommendations

  • Enforce browser version reporting through enterprise management and continuously monitor for hosts below 151.0.7922.72
  • Monitor Chrome policy configuration to detect users or attackers modifying ExtensionInstallSources or disabling extension allowlists
  • Track process lineage where chrome.exe spawns unusual child processes or performs suspicious file writes shortly after extension install events

How to Mitigate CVE-2026-17948

Immediate Actions Required

  • Update Google Chrome to 151.0.7922.72 or later on all managed endpoints
  • Audit installed extensions and remove any that are unverified, side-loaded, or unnecessary for business use
  • Restart Chrome after patching to ensure the vulnerable V8 build is no longer loaded in memory

Patch Information

Google addressed CVE-2026-17948 in Chrome Stable 151.0.7922.72. Deployment details are described in the Google Chrome Stable Update. Chromium-based browsers such as Microsoft Edge, Brave, Opera, and Vivaldi should be updated once their vendors ship the corresponding V8 fix.

Workarounds

  • Enforce a Chrome extension allowlist through ExtensionInstallAllowlist and set ExtensionInstallBlocklist to * to block all non-approved extensions
  • Disable developer mode extensions and prohibit side-loading via DeveloperToolsAvailability and ExtensionInstallSources policies
  • Restrict extension installs to the Chrome Web Store and require administrator review before onboarding new extensions
bash
# Example Chrome enterprise policy to block all extensions except an approved allowlist
# Windows registry path: HKLM\Software\Policies\Google\Chrome\

ExtensionInstallBlocklist\1 = "*"
ExtensionInstallAllowlist\1 = "<approved-extension-id-1>"
ExtensionInstallAllowlist\2 = "<approved-extension-id-2>"
DeveloperToolsAvailability = 2
ExtensionInstallSources = "https://chrome.google.com/webstore/*"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.