Researchers have published the full technical details and exploit code for a critical vulnerability remote code execution (RCE) in V8 JavaScript engine Google Chrome's.

The vulnerability, tracked internally as a “WebAssembly type canonicalization bug,” results from an improper nullability check in the CanonicalEqualityEqualValueType function, introduced with change 44171ac in Chrome M135 and above. As a result, no distinction is made between ref t0 and ref null t0, which allows an attacker to create two recursive type groups that collide under the same MurmurHash64A hash value.
By launching a birthday attack on type canonicalization, the exploit achieves nullability confusion on indexed reference types, undermining basic security guarantees . A new V8 sandbox exploits JavaScript Promise Integration (JSPI) state-switching flaws introduced in M137.
See also: PoC Exploit published for zero-day in Oracle E-Business Suite
SSD Secure Disclosure stated that an attacker exploits an intra-state confusion in the secondary stack management logic to move execution between nested JS and Wasm stacks out of order.
The exploit gains full stack control and creates a return-oriented programming chain to call VirtualProtect on a RWX shellcode buffer.
Chrome RCE Vulnerability – Exploit
The proof-of-concept exploit, released for the Chrome vulnerability, includes an HTML payload and accompanying JavaScript that uses wasm-module-builder.js to create bespoke Wasm types and functions.
To deploy the exploit, the user must navigate to https://127.0.0.1:8000/exp.html. A successful exploit will spawn a Windows calc.exe process via a crafted ROP chain and RWX shellcode.
See also: PoC Exploit released for Sudo vulnerability that allows Root access

The exploit script performs the following steps:
1. It records two Wasm recursive type groups (t2null vs. t2nonnull) that differ only in nullability and then uses a birthday attack on 2^32 MurmurHash64A values to detect a collision.
2. Converts a ref null t1 to a ref t1, providing a sandboxed caged read/write primitive. Exploits out-of-bounds access to a large ArrayBuffer.
3. Constructs nested promise-based Wasm exports to force stack switches, and then exploits a lack of SBX_CHECK in commit c6426203, to bypass an inactive stack frame.
4. Sprays a table of gadget addresses—pop rax; jmp rax, VirtualProtect thunk offsets, etc.—to mark shellcode memory as executable.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Use-after-free vulnerability in Redis Server allows RCE

The discovery and exploitation are credited to Seunghyun Lee (0x10n), winner of the Chrome RCE category at TyphoonPWN 2025.Users are urged to update to Chrome M137.0.7151.57 (or newer) as soon as possible to mitigate this critical RCE vulnerability.
