Google Chrome has a new tool to help protect against memory corruption

Google Chrome browser app on iPhone
(Image credit: Shutterstock)

Google just introduced a new feature for its Chrome browser, which should eliminate, or at least minimize, memory corruption vulnerabilities.

It is called V8 Sandbox and described as a “lightweight, in-process sandbox for V8.”

For those who are unaware, V8 is a JavaScript and WebAssembly engine that Google developed for the Chrome browser. It is free and open source, and part of the Chromium project. It is also used in other, non-browser related projects, such as the Node.js runtime system.

Fundamentally cheap approach

In a technical write up published recently, Google said that all Chrome exploits caught in the wild in the last three years (2021 - 2023) started out with a memory corruption vulnerability in a Chrome renderer process that was exploited for remote code execution. The majority of those vulnerabilities (60%) were found in V8.

This motivated the team to look for a solution, and after almost three years building, they came out with the V8 Sandbox, a tool that is “no longer considered an experimental security feature”. The tool is already included in Chrome’s Vulnerability Reward Program (VRP), and in Chrome 123 - which could be considered “a sort of ‘beta’ release for the sandbox,” they said. 

The idea behind V8 Sandbox is not unlike any other sandbox - all the code V8 executes gets restricted to a subset of the process’ virtual address space, and isolated from the rest of the process. 

On the V8 blog, security technical lead Samuel Groß said that the approach is “fundamentally cheap” - the overhead caused by the sandbox is around 1% or less, according to results from Speedometer and JetStream. That means V8 Sandbox can be enabled by default on compatible platforms, meaning Android, ChromeOS, Linux, macOS, and Windows. 

"The V8 Sandbox requires a 64-bit system as it needs to reserve a large amount of virtual address space, currently one terabyte," Groß said.

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A finger touching the google chrome icon in the Windows 10 start menu
A new Chrome browser highjacking attack could affect billions of users - here's how to fight it
New NordLayer browser interface
‘Browsers cannot stay unprotected’ - NordLayer unveils its holistic cybersecurity-focused browser
Google Chrome browser icon
A new split-screen feature is coming to Google Chrome, and it's surprisingly powerful
Woman shocked by online scam, holding her credit card outside
Google Chrome is testing a new AI tool that scans for scams to help save you from online trickery
Chrome icon on Android
Google plans on a handy fix for all those duplicate Chrome tabs, but it's only for Android
chrome firefox extensions
Google Chrome extensions hit in major attack - dozens of developers affected, so be on your guard
Latest in Security
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Passwordless authentication continues to grow, with biometrics helping push adoption
Data leak
Hacked Tata Technologies data leaked by ransomware gang
Latest in News
Tony Hawk's Pro Skater 3+4
From Ace of Spades to Them Bones, Tony Hawk's Pro Skater 3+4's soundtrack is already looking excellent
The Google Gemini logo against a black background.
I tried Gemini's new AI image generation tool - here are 5 ways to get the best art from Google's upcoming Flash 2.0 built-in image upgrade
An image of the Samsung Galaxy S25 Ultra from a hands-on event
Samsung Galaxy S26 Ultra could resurrect an intriguing camera feature
Eurocom Raptor X18
At $15,000, this massive 256GB RAM laptop makes Apple's MacBook Pro look affordable, tiny and very, very slow
Cristin Milioti in Black Mirror season 7
Netflix launches trailer for Black Mirror season 7, giving us a look at its first-ever sequel episode and an unexpected returning character
A graphic of the PC Gaming Show
Get ready for a bounty of PC games on June 8, as the PC Gaming show is back