AI audit uncovers 1-line V8 integer overflow that survived 3.5 years, enabling Chrome RCE

moyix · x · 2026-09-06

Security firm QEDAudit disclosed CVE-2026-19174, an integer overflow in Chrome's V8 engine that enables arbitrary code execution from a single line of constant arithmetic. The bug survived 3.5+ years of fuzzing, manual audits, and LLM-driven review. The auditor notes that on returning to browser/JSE vulnerability research, AI agents were finding and exploiting bugs everywhere — and it was in this process that the long-lived one-line bug surfaced.

Related event: AI Audit Uncovers 3.5-Year-Old V8 Integer Overflow Flaw(2 posts)→

Original post →

More from Safety

Safety channel →