FAIL › dossier
Chromium V8
PRODUCT· dossier confidence 40%
Google Chromium V8 is a critical open-source engine powering Chrome and ChromeOS, maintaining a high-velocity patching cadence that resulted in five zero-days in 2026, including two high-severity RCEs.
PROFILE
CategorySoftware ProductWhat they doGoogle Chromium V8 is the JavaScript engine powering the Chromium web browser and ChromeOS, developed by Google.Founded2008
Websitehttps://chromium.org ↗
SECURITY POSTURE
Google Chromium V8 demonstrates a high-volume vulnerability response capability, evidenced by the patching of five zero-day vulnerabilities in 2026 alone, including two high-severity RCEs in V8.
Notable failures
- CVE-2026-3910: High-severity RCE via crafted HTML pages
- CVE-2026-11645: High-severity RCE via sandbox escape and out-of-bounds read/write
- CVE-2026-11645: Exploited in the wild before patching
Patterns: Repeated high-severity RCEs in V8 engine; Sandbox escape vulnerabilities; Out-of-bounds read/write flaws
FAILURE HISTORY · 39
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-03-13 | CVE-2026-3910 | high | Google Chromium V8 allows remote code execution via crafted HTML pages, enabling attackers to bypass sandbox protections. |
| 2021-11-03 | CVE-2021-21220 | high | A remote attacker could exploit heap corruption via a crafted HTML page in Google Chromium V8 to execute arbitrary code. |
| 2021-11-03 | CVE-2021-30632 | high | An out-of-bounds write vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2021-11-03 | CVE-2021-21148 | high | A heap buffer overflow in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2021-11-03 | CVE-2021-30551 | high | A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2021-11-03 | CVE-2021-21224 | high | A type confusion vulnerability in Google Chromium V8 allowed remote code execution inside a browser sandbox via a crafted HTML page. |
| 2022-04-15 | CVE-2022-1364 | high | A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2022-03-28 | CVE-2022-1096 | high | A type confusion vulnerability in Google's Chromium V8 engine allowed remote attackers to exploit heap corruption via crafted HTML pages. |
| 2021-12-15 | CVE-2021-4102 | high | A use-after-free vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2021-11-03 | CVE-2020-16009 | high | A type confusion vulnerability in Google's Chromium V8 engine allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2021-11-03 | CVE-2021-37975 | high | A use-after-free vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2021-11-03 | CVE-2021-30563 | high | A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2021-11-03 | CVE-2020-6418 | high | A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2025-11-19 | CVE-2025-13223 | high | Google Chromium V8 heap corruption |
| 2025-09-23 | CVE-2025-10585 | high | Google Chromium V8 had an unpatched type confusion vulnerability actively exploited in the wild |
| 2025-07-02 | CVE-2025-6554 | high | Google Chromium V8 had a type confusion vulnerability exploited in the wild |
| 2025-06-05 | CVE-2025-5419 | high | Google Chromium V8 OOB Read/Write Vuln exploited |
| 2023-06-07 | CVE-2023-3079 | high | Google Chromium V8 Type Confusion Vulnerability allows remote code execution. |
| 2023-04-17 | CVE-2023-2033 | high | Google Chromium V8 Type Confusion Vulnerability allows remote code execution. |
| 2022-12-05 | CVE-2022-4262 | high | Google Chromium V8 Engine had a type confusion vulnerability actively exploited in the wild |
| 2022-10-28 | CVE-2022-3723 | high | Google Chromium V8 Engine had a type confusion vulnerability actively exploited in the wild |
| 2022-06-08 | CVE-2019-5825 | high | A heap corruption vulnerability in Google's Chromium V8 engine was actively exploited, impacting browsers like Chrome and Edge, potentially allowing attackers to execute arbitrary code via a crafted HTML page. |
| 2022-06-08 | CVE-2018-17463 | high | A Chromium V8 vulnerability allowed remote code execution via crafted HTML, impacting multiple browsers and potentially DIB organizations using them for web access or internal tools. |
| 2022-06-08 | CVE-2016-1646 | high | A Chromium V8 out-of-bounds read vulnerability was actively exploited, impacting browsers like Chrome and Edge, potentially causing denial of service or other impacts. |
| 2022-06-08 | CVE-2018-6065 | high | A heap corruption vulnerability in Google's Chromium V8 engine was actively exploited, impacting browsers like Chrome and Edge, potentially allowing attackers to execute arbitrary code via crafted HTML pages. |
| 2022-06-08 | CVE-2018-17480 | high | A Chromium V8 out-of-bounds write vulnerability allowed remote code execution via crafted HTML, impacting multiple browsers including Chrome and Edge, and is currently being exploited in the wild. |
| 2022-06-08 | CVE-2017-5030 | high | A memory corruption vulnerability in Google's Chromium V8 engine allowed remote code execution via crafted HTML pages, impacting multiple browsers including Chrome and Edge, and actively exploited in the wild. |
| 2026-06-09 | CVE-2026-11645 | high | Google Chromium V8 allows remote code execution via crafted HTML pages, enabling sandbox escape and arbitrary code execution. |
| 2024-05-20 | CVE-2024-4947 | high | Google Chromium V8 allows remote code execution via a type confusion vulnerability in a crafted HTML page. |
| 2022-06-08 | CVE-2016-5198 | high | A Chromium V8 out-of-bounds memory vulnerability enabled remote code execution in multiple browsers, including those used within the DIB, and was actively exploited in the wild. |
| 2021-11-03 | CVE-2020-16013 | high | A heap corruption vulnerability in Google Chromium V8 allowed remote attackers to exploit crafted HTML pages, affecting multiple Chromium-based browsers. |
| 2021-11-03 | CVE-2021-38003 | high | A memory corruption bug in Google Chromium V8's JSON.stringify function leaked internal data to script code, causing corruption across multiple Chromium-based browsers. |
| 2022-06-08 | CVE-2017-5070 | high | A type confusion vulnerability in Google's Chromium V8 engine allowed remote code execution via crafted HTML pages, impacting multiple browsers including Chrome and Edge, and actively exploited in the wild. |
| 2024-08-28 | CVE-2024-7965 | high | Google Chromium V8 allows remote attackers to exploit heap corruption via crafted HTML pages, affecting all Chromium-based browsers. |
| 2024-08-26 | CVE-2024-7971 | high | Google Chromium V8 exploited a remote type confusion vulnerability allowing heap corruption via crafted HTML. |
| 2024-05-28 | CVE-2024-5274 | high | Google Chromium V8 Type Confusion Vulnerability allows remote code execution via crafted HTML pages. |
| 2024-05-16 | CVE-2024-4761 | high | Google Chromium V8 engine contains an out-of-bounds memory write vulnerability exploitable via crafted HTML pages. |
| 2024-02-06 | CVE-2023-4762 | high | Google Chromium V8 Type Confusion Vulnerability allows remote code execution via crafted HTML pages. |
| 2024-01-17 | CVE-2024-0519 | high | Google Chromium V8 engine contains an out-of-bounds memory access vulnerability that allows remote attackers to exploit heap corruption via crafted HTML pages. |
DOSSIER SOURCES
- Alphabet (GOOGL) Company Profile & Description - Stock Analysis · stockanalysis.com
- Profile - CRDO - NASDAQ - Weiss Ratings · weissratings.com
- Chromium (web browser) - Wikipedia · en.wikipedia.org
- Chrome Releases · chromereleases.googleblog.com
- Google Patches 5th Chrome Zero-Day; V8 Flaw Chains for OS Access · dailysecurityreview.com
- Chrome CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
Open questions: Patch status for CVE-2026-3910 and CVE-2026-11645 · Impact on deployed enterprise systems
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-14 03:59:07.801310+00:00