
👀 (CVE-2026-2649)[481074858][wasm][turboshaft]Wasm br_table operation Phi integer overflow(passing too many inputs). https://chromium.googlesource.com/v8/v8/+/04d57e1a869ae90d812cc66eb5946b42069558e8 https://chromium.googlesource.com/v8/v8/+/25613a3e9b8240326004e2c2f08954237eed21dc https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_18.html PoC: ./d8 --no-liftoff https://chromium.googlesource.com/v8/v8/+/25613a3e9b8240326004e2c2f08954237eed21dc/test/filecheck/wasm/crash/regress-481074858.js Reported by JunYoung Park(@siwu_network) https://t.co/MjYU6bPAkD
Post summary
The post announces CVE‑2026‑2649, a Wasm integer overflow in V8, provides a working PoC and technical details, but offers no evidence of active exploitation or patch guidance.







