CVE-2026-2649Disclosure(google / chrome)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch google chrome systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Integer overflow in V8 in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-472

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 4 mentions (2026-02-19); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
chrome

Deep dive

Activity timeline8 mentions / 5d
01234Mentions · 2026-02-18: 1Mentions · 2026-02-19: 4Mentions · 2026-02-20: 1Mentions · 2026-02-23: 1Mentions · 2026-02-24: 1PoC Mentioned / Linked · 2026-02-19: 1Exploit Tool / Code · 2026-02-19: 1Patch / Workaround · 2026-02-19: 2Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-02-24: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-19: 3Technical Details · 2026-02-20: 1Technical Details · 2026-02-24: 102-1802-1902-2002-2302-24
Signal classification4 categories
Disclosure
337.5%
Patch
337.5%
PoC
112.5%
General
112.5%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-02-181
Disclosure1
2026-02-194
Disclosure2Patch1PoC1
2026-02-201
Patch1
2026-02-231
General1
2026-02-241
Patch1
Full discourse8 posts
  • xvonfers@xvonfers
    PoC

    👀 (CVE-2026-2649)[481074858][wasm][turboshaft]Wasm br_table operation Phi integer overflow(passing too many inputs). https://chromium.googlesource.com/v8/v8/+/04d57e1a869ae90d812cc66eb5946b42069558e8 https://chromium.googlesource.com/v8/v8/+/25613a3e9b8240326004e2c2f08954237eed21dc https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_18.html PoC: ./d8 --no-liftoff https://chromium.googlesource.com/v8/v8/+/25613a3e9b8240326004e2c2f08954237eed21dc/test/filecheck/wasm/crash/regress-481074858.js Reported by JunYoung Park(@siwu_network) https://t.co/MjYU6bPAkD

    Post summary

    The post announces CVE‑2026‑2649, a Wasm integer overflow in V8, provides a working PoC and technical details, but offers no evidence of active exploitation or patch guidance.

    17031202.6K
    4.8K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Google Pushes Emergency Chrome Patch for High-Severity PDFium & V8 Flaws (CVE-2026-2648/2649) Google released an emergency Chrome Stable update (145.0.7632.109/110 for Windows/macOS; 144.0.7559.109 for Linux) fixing two high-severity memory issues—PDFium heap buffer overflow (CVE-2026-2648) and a V8 integer overflow (CVE-2026-2649)—plus a Media heap overflow (CVE-2026-2650). This matters because these core-engine bugs can enable crashes or arbitrary code execution via malicious content, so rapid patching reduces browser RCE risk across enterprises. 🎯 Target: Global #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/google-chrome-emergency-security-update/

    Post summary

    Google released an emergency Chrome patch addressing high‑severity PDFium and V8 memory overflows that could lead to arbitrary code execution.

    00001108
    196 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Google releases an urgent Chrome update to patch high-severity flaws in PDFium (CVE-2026-2648) and the V8 engine (CVE-2026-2649). Update to 145 now. #ChromeUpdate #CyberSecurity #InfoSec #CVE20262648 #V8Engine #PatchNow https://securityonline.info/urgent-chrome-patch-google-fixes-high-severity-pdf-and-v8-engine-flaws/

    Post summary

    Google has issued an urgent Chrome update (v145) to patch high‑severity CVEs in PDFium and V8. No exploitation or PoC details are provided.

    00001186
    10.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2649 Integer Overflow in Google Chrome V8 Enables Remote Heap Corruption Exploit https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2649

    Post summary

    This entry reports the integer overflow vulnerability CVE-2026-2649 in Chrome’s V8 engine that can lead to remote heap corruption, but does not provide any PoC, exploit, or patch details.

    0001083
    4.0K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Google ❗ CVE-2026-2649 ❗ CVE-2026-2648 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-google-2/ https://t.co/PEnhwK5AvC

    Post summary

    The post lists two CVEs affecting Google products and points to external links for more information, but provides no further details.

    00000121
    6.6K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A High severity integer overflow (CVE-2026-2649) in `chromium` V8 could lead to heap corruption via crafted HTML. Patching is recommended when updates are available. #Chromium #V8 #InfoSec https://www.pulsepatch.io/posts/cve-2026-2649-chromium-v8-integer-overflow

    Post summary

    CVE-2026-2649 is a high‑severity integer overflow in Chromium V8 that can cause heap corruption via crafted HTML; users should apply available patches.

    0000033
    1 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 HIGH severity: Integer overflow in Chrome V8 (pre-145.0.7632.109) puts users at risk of remote code execution via malicious HTML. Update now! 🛡️ https://radar.offseq.com/threat/cve-2026-2649-integer-overflow-in-google-chrome-1776d2df #OffSeq #Chrome #Vulnerability https://t.co/AyTk5swIHz

    Post summary

    The tweet announces a high‑severity integer overflow in Chrome V8 that permits remote code execution through malicious HTML and urges users to update to mitigate the risk.

    0000042
    265 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2649 Integer overflow in V8 in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium secu… https://www.cve.org/CVERecord?id=CVE-2026-2649

    Post summary

    CVE‑2026‑2649 discloses an integer overflow in Chrome's V8 engine that could cause heap corruption when a crafted HTML page is loaded.

    00000164
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---

Explore more