CVE-2026-19174: one-line V8 integer overflow gives Chrome RCE, evaded review for 3.5 years
evilsocket · x · 2026-09-06
Security audit team QEDAudit disclosed CVE-2026-19174, an integer overflow in the V8 engine enabling arbitrary code execution in Chrome.
- Root cause is just one line of constant arithmetic
- Survived 3.5 years of fuzzing, manual audit, and LLM-driven code review
- Highlights systematic blind spots in automated security tooling, including LLM-based review, for subtle logic bugs
More from Safety
- xAI fails to block Minnesota's AI nudification ban; lawsuit continues — VraserX · 2026-09-06
- 15 frontier LLMs: 94% of correct medical answers fail under adversarial pressure — davidmanheim · 2026-09-06
- Google's always-on Gemini Spark agent handles photos and trips, raising fresh privacy questions — emmanuelvivier · 2026-09-06
- Los Angeles school district bans generative AI in schools for one year — emmanuelvivier · 2026-09-06
- OpenAI expands Daybreak program to water and power services for cyber defense — emmanuelvivier · 2026-09-06
- Seattle Times and Newsday sue OpenAI/Microsoft; Altman apologizes for chaotic GPT-6 launch — emmanuelvivier · 2026-09-06