CVE-2026-84326CWE-908

CVE-2026-84326

High · published September 2, 2026

CVSS v3.1
8.8
EPSS
0%
Percentile
19.6
In the wild
Unconfirmed
What it is

Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00275 · 19.6th percentile
Weakness
CWE-908 · Use of Uninitialized Resource
Published
2026-09-02T04:18Z
Affected products (1)
ProductVersionsFixed in
google/chrome< 152.0.7977.75152.0.7977.75
References (2)
EPSS history
Timeline
  • 03 SEP 03:32Z
    EPSS moved — → 0%
    epss
  • 01 SEP 23:42Z
    Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML…
    cvelistv5