Description
Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-10-02
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A type‑confusion flaw in the V8 JavaScript engine of Google Chrome allows a remote attacker to execute arbitrary code inside the browser sandbox by serving a specially crafted HTML page. This vulnerability is classified as high severity in Chromium’s own assessment and could lead to compromise of the user's machine if the sandbox escapes. The flaw involves a mismatch between expected and actual object types, enabling the attacker to manipulate the engine’s behavior and run code that the sandbox normally rejects.

Affected Systems

All installations of Google Chrome that use the V8 engine and are running a version prior to 154.0.8037.97 are impacted. No specific version ranges beyond this lower bound are listed; the vendor does not provide a detailed list of affected releases, so any older stable channel build is considered vulnerable.

Risk and Exploitability

Chromium assigns this bug a high severity, but no EPSS score is available and it is not listed in CISA’s KEV catalog. The exploit requires the attacker to serve a malicious HTML page that a user opens or visits; thus the attack vector is web‑based and the impact is limited to the local user session unless the user also runs privileged extensions or plugins. Given the high severity and the lack of mitigation, the risk to systems that open untrusted content is significant.

Generated by OpenCVE AI on October 2, 2026 at 17:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 154.0.8037.97 or newer.
  • Confirm that automatic browser updates are enabled to receive subsequent security patches without manual intervention.
  • When upgrade delay is unavoidable, configure restrictive content‑security policies or disable JavaScript for untrusted web pages to reduce the attack surface.

Generated by OpenCVE AI on October 2, 2026 at 17:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Type Confusion in Chrome V8 Engine

Fri, 02 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-843
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-02T16:07:55.104Z

Reserved: 2026-09-30T23:12:17.588Z

Link: CVE-2026-103625

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T16:16:43.610

Modified: 2026-10-02T17:47:56.067

Link: CVE-2026-103625

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:30:18Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')