
Proof-of-concept exploit for CVE-2026-4447, a V8 RCE in Google Chrome prior to 146.0.7680.153, allowing arbitrary code execution via crafted HTML pages.
python3 exploit.py -t "C:\\Path\\To\\Target" -o demo.zip --data-file payload.exe
Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Google Chrome: