CVE-2026-1220Patch(apple / chrome)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-01-28); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-01-28: 1Mentions · 2026-01-29: 1Mentions · 2026-01-30: 1Patch / Workaround · 2026-01-28: 1Technical Details · 2026-01-28: 1Technical Details · 2026-01-29: 101-2801-2901-30
Signal classification3 categories
Patch
133.3%
General
133.3%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-281
Patch1
2026-01-291
General1
2026-01-301
Disclosure1
Full discourse3 posts
  • iototsecnews@iototsecnews
    Patch

    Chrome 144 の脆弱性 CVE-2026-1220 が FIX:V8 JavaScript エンジンの競合状態 https://iototsecnews.jp/2026/01/21/chrome-144-released-to-fix-high-severity-v8-javascript-engine-flaw/ Google Chrome の V8 JavaScript エンジンに、アカウント乗っ取りの恐れのある深刻な脆弱性 CVE-2026-1220 が見つかりました。この問題の原因は、プログラムが複数の処理を同時に行う際に発生する、レース・コンディション (競合状態) という設計上の不備にあります。 具体的には、V8 エンジンがデータの読み書きを行う際、複数の処理が適切な順番を守らずに、共有メモリへ同時にアクセスする状況が生じます。この隙を攻撃者に悪用され、メモリの内容が書き換えられてしまうと、ブラウザ上での任意のコード実行に至る可能性があります。ご利用のチームは、ご注意ください。よろしければ、Chrome での検索結果も、ご参照ください。 #Chrome #CVE20261220 #Google #Vulnerability

    Post summary

    A high‑severity race condition flaw (CVE‑2026‑1220) in Chrome’s V8 JavaScript engine has been discovered, allowing potential arbitrary code execution; the vulnerability is fixed in Chrome 144.

    01000215
    485 followersView on X
  • cybach@CybachOy
    Disclosure

    A vulnerability in Microsoft Edge has been disclosed, affecting versions prior to 144.0.3719.92. The issue, referenced as CVE-2026-1220, could allow an attacker to cause an unspecified security proble https://pigeonreporter.com/2026/01/28/vulnerability-in-microsoft-edge-disclosed

    Post summary

    Microsoft Edge vulnerability CVE-2026-1220 disclosed for versions prior to 144.0.3719.92, but the description is vague and lacks detail or actionable information.

    0000048
    7 followersView on X
  • Aakash Rahsi@rahsi_aaka
    General

    CVE-2026-1220 | Chromium: CVE-2026-1220 Race in V8 https://www.aakashrahsi.online/post/cve-2026-1220 https://t.co/S28n6Wz6Nx

    Post summary

    The tweet links to a blog post about CVE‑2026‑1220, a race condition in Chromium’s V8 engine. No PoC, exploit code, patch, or active exploitation claims are included.

    0000050
    2 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more