CVE-2026-1220
Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page.
CVSS
7.5
High
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Published: Jun 10, 2026 · Last modified: Jul 23, 2026 · CWE-362
0.3%EPSS · 30 days0.3%
2026-08-112026-09-07
Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High)
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-588487.0 HIG—
———In multiple functions of alloc.c, there is a possible unauthorized read/write access due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.9hCVE-2026-778947.0 HIG—
———Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.10hCVE-2026-730057.0 HIG—
———Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.11hCVE-2026-705826.4 MED—
———Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.11hCVE-2026-700915.9 MED—
———Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network.11hCVE-2026-698278.1 HIG—
———Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.11h