EIP-2026-103503

PRE-CVE

Google Chrome V8 JavaScript Engine 71.0.3578.98 - Out-of-Memory. Denial of Service (PoC)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103503. PoCs published by Bogdan Kurinnoy.

AI-analyzed exploit summary This PoC exploits an out-of-memory (OOM) condition in Google Chrome's V8 JavaScript engine by forcing excessive memory allocation via String.prototype.toLowerCase on a large array, leading to a denial of service (DoS). The exploit targets a specific vulnerability in the CALL_AND_RETRY_LAST mechanism.

Description

Google Chrome V8 JavaScript Engine 71.0.3578.98 - Out-of-Memory. Denial of Service (PoC)

Exploits (1)

exploitdb WORKING POC
by Bogdan Kurinnoy · htmldosmultiple
https://www.exploit-db.com/exploits/46099

This PoC exploits an out-of-memory (OOM) condition in Google Chrome's V8 JavaScript engine by forcing excessive memory allocation via String.prototype.toLowerCase on a large array, leading to a denial of service (DoS). The exploit targets a specific vulnerability in the CALL_AND_RETRY_LAST mechanism.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Google Chrome 71.0.3578.98 (V8 7.3.0)
No auth needed
Prerequisites: Google Chrome 71.0.3578.98 with V8 7.3.0
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026