Vulnerability intelligence
CVE-2026-106240
Type confusion in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSS Score
8.8
High
EPSS — Exploit Probability
—
Awaiting FIRST.org data · checked 2026-10-07
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
No linked coverage yet. CyberSIXT tracks this CVE and coverage will appear here.