CVE-2023-3079High· 8.8▾ Abyssal⚠ Exploited in the wildPoC availableType confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 48.4 · likelihood 6.4 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Jun 28, 2023
Last analysed / modified upstream
32%
1 GitHub repo (last check)
Added to the CISA catalog on Jun 7, 2023. Federal remediation due Jun 28, 2023. View catalog ↗
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
chrome < 114.0.5735.110fedora = 37fedora = 38debian_linux = 11.0debian_linux = 12.0couchbase_server < 7.1.5couchbase_server = 7.2.0Upgrade past the affected range:
chrome 114.0.5735.110couchbase_server 7.1.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85046High· 8.8Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
CVE-2026-5865High· 8.8Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page
CVE-2026-5281High· 8.8Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page
CVE-2026-106341High· 8.8Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page
CVE-2026-106374High· 8.8Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page
CVE-2026-5914High· 8.8Type Confusion in CSS in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension