Skip to content
COOEY

FAIL › dossier

Chromium V8

PRODUCT

· dossier confidence 40%

Google Chromium V8 is a critical open-source engine powering Chrome and ChromeOS, maintaining a high-velocity patching cadence that resulted in five zero-days in 2026, including two high-severity RCEs.

PROFILE
CategorySoftware ProductWhat they doGoogle Chromium V8 is the JavaScript engine powering the Chromium web browser and ChromeOS, developed by Google.Founded2008 Websitehttps://chromium.org ↗
SECURITY POSTURE

Google Chromium V8 demonstrates a high-volume vulnerability response capability, evidenced by the patching of five zero-day vulnerabilities in 2026 alone, including two high-severity RCEs in V8.

Notable failures
  • CVE-2026-3910: High-severity RCE via crafted HTML pages
  • CVE-2026-11645: High-severity RCE via sandbox escape and out-of-bounds read/write
  • CVE-2026-11645: Exploited in the wild before patching
Patterns: Repeated high-severity RCEs in V8 engine; Sandbox escape vulnerabilities; Out-of-bounds read/write flaws
FAILURE HISTORY · 39
DATEEVENTSEVSUMMARY
2026-03-13 CVE-2026-3910 high Google Chromium V8 allows remote code execution via crafted HTML pages, enabling attackers to bypass sandbox protections.
2021-11-03 CVE-2021-21220 high A remote attacker could exploit heap corruption via a crafted HTML page in Google Chromium V8 to execute arbitrary code.
2021-11-03 CVE-2021-30632 high An out-of-bounds write vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
2021-11-03 CVE-2021-21148 high A heap buffer overflow in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
2021-11-03 CVE-2021-30551 high A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
2021-11-03 CVE-2021-21224 high A type confusion vulnerability in Google Chromium V8 allowed remote code execution inside a browser sandbox via a crafted HTML page.
2022-04-15 CVE-2022-1364 high A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
2022-03-28 CVE-2022-1096 high A type confusion vulnerability in Google's Chromium V8 engine allowed remote attackers to exploit heap corruption via crafted HTML pages.
2021-12-15 CVE-2021-4102 high A use-after-free vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
2021-11-03 CVE-2020-16009 high A type confusion vulnerability in Google's Chromium V8 engine allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
2021-11-03 CVE-2021-37975 high A use-after-free vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
2021-11-03 CVE-2021-30563 high A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
2021-11-03 CVE-2020-6418 high A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
2025-11-19 CVE-2025-13223 high Google Chromium V8 heap corruption
2025-09-23 CVE-2025-10585 high Google Chromium V8 had an unpatched type confusion vulnerability actively exploited in the wild
2025-07-02 CVE-2025-6554 high Google Chromium V8 had a type confusion vulnerability exploited in the wild
2025-06-05 CVE-2025-5419 high Google Chromium V8 OOB Read/Write Vuln exploited
2023-06-07 CVE-2023-3079 high Google Chromium V8 Type Confusion Vulnerability allows remote code execution.
2023-04-17 CVE-2023-2033 high Google Chromium V8 Type Confusion Vulnerability allows remote code execution.
2022-12-05 CVE-2022-4262 high Google Chromium V8 Engine had a type confusion vulnerability actively exploited in the wild
2022-10-28 CVE-2022-3723 high Google Chromium V8 Engine had a type confusion vulnerability actively exploited in the wild
2022-06-08 CVE-2019-5825 high A heap corruption vulnerability in Google's Chromium V8 engine was actively exploited, impacting browsers like Chrome and Edge, potentially allowing attackers to execute arbitrary code via a crafted HTML page.
2022-06-08 CVE-2018-17463 high A Chromium V8 vulnerability allowed remote code execution via crafted HTML, impacting multiple browsers and potentially DIB organizations using them for web access or internal tools.
2022-06-08 CVE-2016-1646 high A Chromium V8 out-of-bounds read vulnerability was actively exploited, impacting browsers like Chrome and Edge, potentially causing denial of service or other impacts.
2022-06-08 CVE-2018-6065 high A heap corruption vulnerability in Google's Chromium V8 engine was actively exploited, impacting browsers like Chrome and Edge, potentially allowing attackers to execute arbitrary code via crafted HTML pages.
2022-06-08 CVE-2018-17480 high A Chromium V8 out-of-bounds write vulnerability allowed remote code execution via crafted HTML, impacting multiple browsers including Chrome and Edge, and is currently being exploited in the wild.
2022-06-08 CVE-2017-5030 high A memory corruption vulnerability in Google's Chromium V8 engine allowed remote code execution via crafted HTML pages, impacting multiple browsers including Chrome and Edge, and actively exploited in the wild.
2026-06-09 CVE-2026-11645 high Google Chromium V8 allows remote code execution via crafted HTML pages, enabling sandbox escape and arbitrary code execution.
2024-05-20 CVE-2024-4947 high Google Chromium V8 allows remote code execution via a type confusion vulnerability in a crafted HTML page.
2022-06-08 CVE-2016-5198 high A Chromium V8 out-of-bounds memory vulnerability enabled remote code execution in multiple browsers, including those used within the DIB, and was actively exploited in the wild.
2021-11-03 CVE-2020-16013 high A heap corruption vulnerability in Google Chromium V8 allowed remote attackers to exploit crafted HTML pages, affecting multiple Chromium-based browsers.
2021-11-03 CVE-2021-38003 high A memory corruption bug in Google Chromium V8's JSON.stringify function leaked internal data to script code, causing corruption across multiple Chromium-based browsers.
2022-06-08 CVE-2017-5070 high A type confusion vulnerability in Google's Chromium V8 engine allowed remote code execution via crafted HTML pages, impacting multiple browsers including Chrome and Edge, and actively exploited in the wild.
2024-08-28 CVE-2024-7965 high Google Chromium V8 allows remote attackers to exploit heap corruption via crafted HTML pages, affecting all Chromium-based browsers.
2024-08-26 CVE-2024-7971 high Google Chromium V8 exploited a remote type confusion vulnerability allowing heap corruption via crafted HTML.
2024-05-28 CVE-2024-5274 high Google Chromium V8 Type Confusion Vulnerability allows remote code execution via crafted HTML pages.
2024-05-16 CVE-2024-4761 high Google Chromium V8 engine contains an out-of-bounds memory write vulnerability exploitable via crafted HTML pages.
2024-02-06 CVE-2023-4762 high Google Chromium V8 Type Confusion Vulnerability allows remote code execution via crafted HTML pages.
2024-01-17 CVE-2024-0519 high Google Chromium V8 engine contains an out-of-bounds memory access vulnerability that allows remote attackers to exploit heap corruption via crafted HTML pages.
Open questions: Patch status for CVE-2026-3910 and CVE-2026-11645 · Impact on deployed enterprise systems
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-14 03:59:07.801310+00:00