Google Chrome
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*, +1 more
- < 138.0.7204.168
A type confusion vulnerability has been identified in the V8 JavaScript engine used by Google Chrome. This issue, present in Chrome versions prior to 138.0.7204.168, could allow a remote attacker to exploit heap corruption by crafting a malicious HTML page. The vulnerability has been rated high severity by Chromium security.
Exploitation of this vulnerability could lead to heap corruption, a common precursor to memory corruption vulnerabilities that can be exploited to execute arbitrary code.
Users can update to Google Chrome version 138.0.7204.168 or later to address this vulnerability. The update is being rolled out gradually, with the desktop version available for Windows, Mac, and Linux.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.